Authorization-aware training and serving of machine-learned models

Authorization-aware training and serving of machine-learned models address the risk of data leakage by segregating training datasets and user access, ensuring secure and efficient model usage.

WO2025165346A1PCT designated stage Publication Date: 2025-08-07GOOGLE LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/013475
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-30
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Machine-learned models trained on secure data risk exposing or 'leaking' sensitive information, particularly when prompted with seemingly innocuous instructions, compromising data security.

Method used

Implement authorization-aware training and serving of machine-learned models by dividing training datasets into subsets based on access authorization, training separate models on these subsets, and selecting appropriate models for inference requests based on user authorization to prevent unauthorized access to private data.

Benefits of technology

Prevents unauthorized disclosure of private training data during inference, enhancing data security and reducing computational costs while maintaining privacy and security, thus minimizing energy consumption and environmental impact.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024013475_07082025_PF_FP_ABST
    Figure US2024013475_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Systems and methods are provided for authorization-aware training and serving of machine-learned models to ensure data security of private training data. A training dataset can be divided into subsets based on access authorization data. The subsets can include one or more subsets containing only shared or public data and one or more subsets containing private data that some entities (e.g., users) may be prohibited from accessing. A first machine-learned model can be trained using the shared or public subsets. A second machine-learned model can be trained using the first machine-learned model and one or more private data subsets.
Need to check novelty before this filing date? Find Prior Art

Description

AUTHORIZATION-AWARE TRAINING AND SERVING OF MACHINE-LEARNEDMODELSFIELD

[0001] The present disclosure relates generally to machine learning processes and machine-learned devices and systems. More particularly, the present disclosure relates to systems and methods for preserving data security and preventing data leakage in machine- learned models.BACKGROUND

[0002] A computer can receive input(s). The computer can execute instructions to process the input(s) to generate output(s) using a parameterized model. The computer can obtain feedback on its performance in generating the outputs with the model. The computer can generate feedback by evaluating its performance. The computer can receive feedback from an external source. The computer can update parameters of the model based on the feedback to improve its performance. In this manner, the computer can iteratively “learn” to generate the desired outputs. The resulting model is often referred to as a machine-learned model.

[0003] In some instances, training a machine-learned model on secure data (e.g., data subject to one or more data security controls) can have benefits (e.g., improved inference accuracy with respect to a particular task or data domain, etc.). However, in some instances, machine-learned models can expose or “leak” the secure data used to train the machine- learned model. For example, data security research has indicated that large language models can sometimes output sensitive data used to train the model when prompted with seemingly innocuous instructions, such as asking the model to repeat a certain word indefinitely.SUMMARY

[0004] Aspects and advantages of embodiments of the present disclosure will be set forth in part in the following description, or can be learned from the description, or can be learned through practice of the embodiments.

[0005] Example aspects of the present disclosure provide an example method. In some implementations, the example method can include obtaining, by one or more computing devices, a training dataset comprising a plurality of data items. The example method caninclude obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item. The example method can include determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset. In the example method, the access authorization data can indicate that a first entity is authorized to access each data item of the first subset. In the example method, the access authorization data can indicate that a second entity is authorized to access each data item of the first subset. The example method can include determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset. In the example method, the access authorization data can indicate that the first entity is authorized to access each data item of the second subset. In the example method, the access authorization data can indicate that the second entity7is not authorized to access at least one data item of the second subset. The example method can include training, by the one or more computing devices based on the first subset, a first machine-learned model. The example method can include training, by the one or more computing devices based on the first machine-learned model and the second subset, a second machine-learned model.

[0006] In the example method, training the second model can include initializing a first plurality of parameters of the second machine-learned model based on one or more parameters of the first machine-learned model. In the example method, training the second model can include training a second plurality of parameters of the second machine-learned model using the second subset of the training dataset. In the example method, the second plurality of parameters can be different from the first plurality of parameters. In the example method, the second model can be trained without updating the first plurality of parameters using any data of the second subset of the training dataset.

[0007] In the example method, the first machine-learned model can be a model that was trained based at least in part on a third machine-learned model. In the example method, the third machine-learned model can be a model that was trained on a third plurality of data items. In the example method, the first entity can be authorized to access each data item of the third plurality of data items.

[0008] In the example method, the first machine-learned model can be a model that was trained by : initializing a first plurality of parameters of the first machine-learned model based on one or more parameters of the third machine-learned model; and training a second plurality of parameters of the first machine-learned model using the first subset of the trainingdataset. In the example method, the second plurality of parameters can be different from the first plurality of parameters. In the example method, the first machine-learned model can be a model that was trained without updating the first plurality of parameters using any data item of the third plurality of data items.

[0009] The example method can include receiving, by the one or more computing devices, an inference request associated with the first entity. The example method can include selecting, by the one or more computing devices based on the access authorization data, the second machine-learned model. The example method can include generating, by the one or more computing devices using the second machine-learned model based on the inference request, an output. The example method can include providing, by the one or more computing devices to the first entity, the output.

[0010] The example method can include receiving, by the one or more computing devices, an inference request associated with the second entity. The example method can include selecting, by the one or more computing devices based on the access authorization data, the first machine-learned model. The example method can include generating, by the one or more computing devices using the first machine-learned model based on the inference request, an output. The example method can include providing, by the one or more computing devices to the second entity, the output.

[0011] Example aspects of the present disclosure provide another example method. In some implementations, the example method can include receiving, by one or more computing devices, an inference request from a requester. The example method can include obtaining, by the one or more computing devices, access authorization data indicating that the requester is authorized to access one or more first data items and that the requester is not authorized to access one or more second data items. The example method can include obtaining, by the one or more computing devices, a plurality' of respective machine-learned models trained using a plurality of respective datasets. In the example method, the plurality of respective machine- learned models can contain at least: a first machine-learned model that was trained using training data comprising the one or more second data items; and a second machine-learned model that was not trained using training data comprising the one or more second data items. The example method can include selecting, by the one or more computing devices based on the access authorization data, a machine-learned model of the plurality of machine-learned models. The example method can include generating, by the one or more computing devices based on the inference request using the selected machine-learned model, an output. The example method can include providing, by the one or more computing devices, the output tothe requester. In the example method, the selected model can be the second machine-learned model.

[0012] The example method can include selecting, by the one or more computing devices based on the access authorization data, an additional machine-learned model of the plurality7of machine-learned models. In the example method, the additional model can be different from the second machine-learned model. In the example method, the additional model can be a model that was not trained using training data comprising the one or more second data items. In the example method, the output can be generated using the second machine-learned model and the additional machine-learned model.

[0013] In the example method, generating an output can include generating, by the one or more computing devices using the second machine-learned model based on the inference request, a first inference. In the example method, generating an output can include generating, by the one or more computing devices using the additional machine-learned model based on the inference request, a second inference. In the example method, generating an output can include generating the output based on the first inference and second inference.

[0014] In the example method, generating the output based on the first inference and second inference can include machine-learned reconciliation of the first inference and second inference.

[0015] In the example method, machine-learned reconciliation of the first inference and second inference can include prompting a machine-learned sequence processing model with the first inference and second inference.

[0016] The example method can include retrieving, based at least in part on the access authorization data, at least one of the one or more first data items. In the example method, the output can be generated based at least in part on the one or more retrieved data items.

[0017] The example method can include obtaining, by the one or more computing devices, a second inference request from a second requester. The example method can include obtaining, by the one or more computing devices, access authorization data indicating that the second requester is authorized to access the one or more second data items. The example method can include selecting, by the one or more computing devices based on the access authorization data, the first machine-learned model. The example method can include generating, by the one or more computing devices using the first machine-learned model, a second output. The example method can include providing, by the one or more computing devices, the second output to the second requester.

[0018] In the example method, the first machine-learned model can be a model that was trained by: obtaining, by one or more computing devices, a training dataset comprising a plurality of data items; obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item; determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset, wherein the access authorization data indicates that an entity is authorized to access each data item of the first subset; determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset, wherein the access authorization data indicates that the entity is not authorized to access at least one data item of the second subset; training, by the one or more computing devices based on the first subset, the second machine-learned model; and training, by the one or more computing devices based on the second machine-learned model and the second subset, the first machine-learned model.

[0019] In the example method, training the first machine-learned model can include initializing a first plurality of parameters of the first machine-learned model based on one or more parameters of the second machine-learned model. In the example method, training the first machine-learned model can include training a second plurality of parameters of the first machine-learned model using one or more of the second data items. In the example method, the second plurality of parameters can be different from the first plurality of parameters. In the example method, the first plurality of parameters can be not updated using any data of the second data items.

[0020] In the example method, the requester can include a user.

[0021] In the example method, the requester can include a computing device associated with an access authorization account.

[0022] Example aspects of the present disclosure provide one or more example non- transitory computer-readable media storing instructions that are executable by one or more processors to cause a computing system to perform example operations. In some implementations, the example operations can include obtaining, by one or more computing devices, a training dataset comprising a plurality of data items. The example operations can include obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item. The example operations can include determining, by the one or more computing devices based on theaccess authorization data, a first subset of the training dataset. In the example operations, the access authorization data can indicate that a first entity is authorized to access each data item of the first subset. In the example operations, the access authorization data can indicate that a second entity is authorized to access each data item of the first subset. The example operations can include determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset. In the example operations, the access authorization data can indicate that the first entity is authorized to access each data item of the second subset. In the example operations, the access authorization data can indicate that the second entity is not authorized to access at least one data item of the second subset. The example operations can include training, by the one or more computing devices based on the first subset, a first machine-learned model. The example operations can include training, by the one or more computing devices based on the first machine-learned model and the second subset, a second machine-learned model.

[0023] Example aspects of the present disclosure provide an example computing system that includes one or more processors and one or more example non-transitory computer-readable media storing instructions that are executable by one or more processors to cause a computing system to perform example operations. In some implementations, the example operations can include obtaining, by one or more computing devices, a training dataset comprising a plurality of data items. The example operations can include obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item. The example operations can include determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset. In the example operations, the access authorization data can indicate that a first entity is authorized to access each data item of the first subset. In the example operations, the access authorization data can indicate that a second entity is authorized to access each data item of the first subset. The example operations can include determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset. In the example operations, the access authorization data can indicate that the first entity is authorized to access each data item of the second subset. In the example operations, the access authorization data can indicate that the second entity is not authorized to access at least one data item of the second subset. The example operations can include training, by the one or more computing devices based on the first subset, a first machine-learned model. The example operations can include training, by the one or morecomputing devices based on the first machine-learned model and the second subset, a second machine-learned model.

[0024] In the example operations, training the second model can include initializing a first plurality of parameters of the second machine-learned model based on one or more parameters of the first machine-learned model. In the example operations, training the second model can include training a second plurality of parameters of the second machine-learned model using the second subset of the training dataset. In the example operations, the second plurality of parameters can be different from the first plurality' of parameters. In the example operations, the second model can be trained without updating the first plurality of parameters using any data of the second subset of the training dataset.

[0025] In the example operations, the first machine-learned model can be a model that was trained based at least in part on a third machine-learned model. In the example operations, the third machine-learned model can be a model that was trained on a third plurality' of data items. In the example operations, the first entity can be authorized to access each data item of the third plurality of data items.

[0026] Other example aspects of the present disclosure are directed to other systems, methods, apparatuses, tangible non-transitory computer-readable media, and devices for performing functions described herein. These and other features, aspects, and advantages of various implementations will become better understood with reference to the following description and appended claims. The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate implementations of the present disclosure and, together with the description, help explain the related principles.BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 is a block diagram of an example computing system according to example implementations of aspects of the present disclosure.

[0028] Figure 2 is a block diagram of an example computing system according to example implementations of aspects of the present disclosure.

[0029] Figure 3 is a block diagram of an example computing system according to example implementations of aspects of the present disclosure.

[0030] Figure 4 is a block diagram of an example computing system according to example implementations of aspects of the present disclosure.

[0031] Figure 5 is a flow chart diagram illustrating an example method according to example implementations of aspects of the present disclosure.

[0032] Figure 6 is a flow chart diagram illustrating an example method according to example implementations of aspects of the present disclosure.

[0033] Figure 7 is a flow chart diagram illustrating an example method according to example implementations of aspects of the present disclosure.

[0034] Figure 8 is a flow chart diagram illustrating an example method for training a machine-learned model according to example implementations of aspects of the present disclosure;

[0035] Figure 9 is a block diagram of an example processing flow for using machine- learned model(s) to process input(s) to generate output(s) according to example implementations of aspects of the present disclosure;

[0036] Figure 10 is a block diagram of an example sequence processing model according to example implementations of aspects of the present disclosure;

[0037] Figure 11 is a block diagram of an example technique for populating an example input sequence for processing by a sequence processing model according to example implementations of aspects of the present disclosure;

[0038] Figure 12 is a block diagram of an example model development platform according to example implementations of aspects of the present disclosure;

[0039] Figure 13 is a block diagram of an example training workflow for training a machine-learned model according to example implementations of aspects of the present disclosure;

[0040] Figure 14 is a block diagram of an inference system for operating one or more machine-learned model(s) to perform inference according to example implementations of aspects of the present disclosure;

[0041] Figure 15 is a block diagram of an example networked computing system according to example implementations of aspects of the present disclosure;

[0042] Figure 16 is a block diagram of an example computing device according to example implementations of aspects of the present disclosure; and

[0043] Figure 17 is a block diagram of an example computing device according to example implementations of aspects of the present disclosure.DETAILED DESCRIPTION

[0044] Generally, the present disclosure is directed to systems and methods for ensuring data security7of private training data used to train machine-learned models. More particularly, systems and methods are provided for efficient authorization-aware training andserving of machine-learned models, wherein a plurality of machine-learned models can be efficiently trained using a plurality of training data subsets. For example, each of the plurality of training data subsets may be associated with a different security level and corresponding access authorization. Each respective machine-learned model can be associated with a respective set of data access authorizations, and each respective machine-learned model can be trained only on data authorized by a corresponding access authorization. At inference time, a computing system can select, based on a user’s data access authorizations, one or more machine-learned models to use when processing the user’s inference request, wherein the selected machine-learned model(s) were trained only on data the user is authorized to access. In this manner, for instance, unauthorized disclosure of private or secure training data can be prevented.

[0045] The plurality of training data subsets can include, for example, one or more public or shared training data subsets. For example, a first training data subset can comprise or consist of public data, wherein every7user is authorized to access every data item in the first training data subset. In some instances, a first machine-learned model can be trained solely on a public or shared training data subset, wherein every user of a plurality7of users (e.g., the general public, a company’s employees, a medical patient and her doctor(s), etc.) is authorized to access the shared data.

[0046] The plurality of training data subsets can also include, for example, one or more private and / or secure training data subsets. Such training data subsets may be associated with security levels which are higher than the one or more public or shared training data subsets referred to above. A second training data subset may consist of, for example, data items that a particular plurality of users are authorized to access (e.g., heart health data accessible to a patient and his cardiologist, etc.). In some instances, a second machine-learned model can be trained based on the second training data subset and a public or shared training data subset. In some instances, training the second machine-learned model can include obtaining a first machine-learned model that w as pretrained on the public or shared training data subset; and fine-tuning the second machine-learned model based on the first machine- learned model and the second training data subset.

[0047] In some instances, fine-tuning can be performed using one or more adapterbased training methods. For example, a first machine-learned model having a plurality7of layers can be trained on a first training data subset (e.g.. a subset consisting of shared or public data). A second machine-learned model can comprise the layers of the first machine- learned model (including, e.g., any weights associated with the layers, etc.), along with one ormore additional parameters (e.g., additional layers, weight modification parameters, etc.). In some instances, the second machine-learned model can be initially configured to generate outputs similar to (e.g., same as) outputs generated by the first machine-learned model on similar inputs. For example, one or more parameters can be initially configured to output values similar to (e.g., same as) values received as input. After initialization, the additional parameters can be trained using a second training data subset (e.g., a subset containing private and / or secure data). After training, the second machine-learned model can be stored as a standalone model or stored as a plurality of additional parameters, configured to be used in combination with the first machine-learned model.

[0048] In some instances, a first plurality of users authorized to access one training data subset may overlap with a second plurality of users authorized to access another training data subset. For example, a third training data subset, which may be associated with a security level which is different to the first and second training data subsets, may include data items that are accessible to some users authorized to access the second training data subset, but inaccessible to other users authorized to access the second training data subset. In some instances, a third machine-learned model can be fine-tuned based on the third training data subset and the second machine-learned model. In some instances, this fine-tuning can be performed by retaining a first plurality of additional parameters associated with the second machine-learned model and adding a second plurality of additional parameters associated with the third machine-learned model.

[0049] In some instances, one or more inference endpoints (e g., APIs, user interfaces such as GUIs, etc.) can be provided for requesting an inference from a machine-learned model of the plurality of machine-learned models. In some instances, an inference endpoint can automatically select, based on a user's data access authorizations, one or more machine- learned models to use when processing the user's inference request. For example, in some instances a single inference endpoint can be provided for a plurality- of requesters (e.g., users) having a plurality of different data access authorizations. Upon receiving an inference request, the inference endpoint can determine the requester's data access authorizations; identify one or more machine-learned models whose training dataset does not include any data that exceeds the requester’s data access authorizations; and provide an output using the one or more machine-learned models. In this manner, for instance, the inference endpoint can ensure that a requester does not gain unauthorized access to private training data.

[0050] Provided systems and methods can have a variety of technical effects and benefits. In some instances, systems and methods of the present disclosure can provideimproved data security relative to alternative systems and methods. In some instances, systems and methods of the present disclosure can provide privacy-preserving and / or security-preserving inference at a reduced computational cost compared to alternative systems and methods.

[0051] For example, provided sy stems and methods can greatly reduce or eliminate a risk of unauthorized training data leakage at inference time. In some instances, alternative methods for preventing leakage of private or sensitive training data can include inferencetime post-processing to detect inference outputs that are likely to contain sensitive information or to detect inference requests that are likely to cause sensitive data leakage. For example, in response to data security research showing that certain prompts can cause leakage of sensitive data, some language model providers have prohibited prompts asking their models to repeat certain words forever. However, such case-by-case detection can in some instances leave a system vulnerable to future data leakages from new ty pes of malicious inference requests. In contrast, systems and methods of the present disclosure can provide inference from machine-learned models trained with no access to unauthorized (e.g.. securely stored) data, which can greatly reduce or eliminate a risk of unauthorized training data leakage at inference time.

[0052] In some instances, systems and methods of the present disclosure can provide privacy-preserving and / or security-preserving machine-learned inference at a reduced cost compared to alternative systems and methods. For example, adapter-based fine-tuning methods of the present disclosure can train models at a reduced computational cost (e g., electricity cost, memory usage, processor usage, etc.) compared to alternative methods for training (e.g., fine-tuning, training from scratch) a machine-learned model on a private dataset. Additionally, providing a single inference endpoint for a plurality’ of requesters may provide reduced computational cost (e.g., memory' usage, processor usage, electricity cost, etc.) compared to providing a plurality' of inference endpoints for the plurality of requesters.

[0053] In another example aspect, example implementations can provide for more energy -efficient training operations or model updates. In some scenarios, increased energy efficiency can provide for less energy to be used to perform a given number of update iterations (e g., less energy’ expended to maintain the model in memory, less energy expended to perform calculations within the model, such as computing gradients, backpropagating a loss, etc.). In some scenarios, increased energy efficiency can provide for more update iterations to be completed for a given energy budget (e.g., a larger quantity of iterations, etc.). In some scenarios, greater expressivity afforded by model architectures and trainingtechniques of the present disclosure can provide for a given level of functionality to be obtained in fewer training iterations, thereby expending a smaller energy budget. In some scenarios, greater expressivity afforded by model architectures and training techniques of the present disclosure can provide for an extended level of functionality to be obtained in a given number of training iterations, thereby more efficiently using a given energy budget.

[0054] In this manner, for instance, the improved energy efficiency of example implementations of the present disclosure can reduce an amount of pollution or other waste associated with implementing machine-learned models and systems, thereby advancing the field of machine-learning and artificial intelligence as a whole. The amount of pollution can be reduced in toto (e.g., an absolute magnitude thereof) or on a normalized basis (e.g., energy per task, per model size, etc.). For example, an amount of CO2 released (e.g., by a power source) in association with training and execution of machine-learned models can be reduced by implementing more energy-efficient training or inference operations. An amount of heat pollution in an environment (e.g., by the processors / storage locations) can be reduced byimplementing more energy-efficient training or inference operations.

[0055] Various example implementations are described herein with respect to the accompanying Figures.Example Systems

[0056] Figure 1 is a block diagram of an example computing system according to the present disclosure, wherein a plurality of machine-learned models can be trained using authorization-aware training. A set of training data 102 can be provided to an authorization- aware training system 104, which can extract shared training data 106 and private and / or secure training data 120 from the training data 102 based on access authorization data associated with the training data 102. The private and / or secure training data 120 may, for example, be stored in a secure computing system operating with one or more appropriate security protocols to prevent unauthorized access to the private and / or secure training data 120 in the secure computing system. A first machine-learned model 112 can generate training outputs 114 based on the shared training data 106, and the authorization-aware training system 104 can provide model updates 11 based on the training outputs 114. A second machine-learned model 122 can be initialized with pretrained initial parameters 118 obtained from the first machine-learned model 112. The second machine-learned model can generate training outputs 124 based on the private and / or secure training data 120. and theauthorization-aware training system 104 can provide model updates 126 based on the training outputs 124.

[0057] Training data 102 can generally include or otherwise represent various types of data. Input(s) 2 can include one type or many different types of data. Training data 102 can include one type or many different ty pes of data. In some instances, training data 102 can comprise a plurality of training examples. In some instances, each respective training example of the training data 102 can be associated with access authorization data indicative of one or more entities (e.g., users, accounts, computing systems, etc.) that are authorized to access the respective training example. In some instances, the training data 102 can comprise one or more data storage units such as documents; databases; database tables or entries; fdes; or other data type. In some instances, a data storage unit can comprise a plurality of training examples. In such instances, each respective training example of a data storage unit can inherit one or more access authorizations from the data storage unit or can be associated with one or more respective access authorizations specific to the respective training example.

[0058] The authorization-aware training system 104 can comprise, for example, one or more computing devices. The authorization-aware training system 104 can be or include one or more software, firmware, or hardware components configured to process training data 102 based on access authorizations associated with the training data 102. In some instances, a computing device or component can comprise one or more computing devices or components described with respect to Figures 15-17.

[0059] The shared training data 106 can include, for example, data configured for shared access by a plurality of entities. Shared training data 106 can generally include or otherwise represent various types of data. Shared training data 106 can include one ty pe or many different types of data. In some instances, shared training data 106 can comprise a plurality of training examples. In some instances, each training example of the shared training data 106 can be a training example of the training data 102. In some instances, each training example of the shared training data 106 can be associated with access authorization data indicating that a respective plurality of entities (e.g., users, accounts, computing systems, etc.) are authorized to access the training example. In some instances, a plurality of full- shared-access entities for the shared training data 106 can exist, wherein each entity of the full-shared-access entities is authorized to access every training example of the shared training data 106. In some instances, the shared training data 106 can be a public dataset, wherein the plurality of full-shared-access entities can comprise the general public. In some instances, the shared training data 106 can comprise every shared-access training example ofthe training data 102, wherein a shared-access training example can be defined as a training example that every entity’ of the full-shared-access entities is authorized to access. In some instances, shared training data 106 can include noised or masked private data, wherein otherwise sensitive data has been modified to permit statistical aggregation of one or more aspects of private data while preserving sensitive or private information of the private data. For example, in some instances shared training data 106 can include noised data configured for differentially private training of a machine-learned model.

[0060] The authorization-aware training system 104 can extract the shared training data 106 from the training data 102 in any appropriate manner (e.g., checking authorization access for each training example and populating the shared data 106 on an example-by- example basis; querying a database using one or more parameters indicative of access authorization data; loading one or more files associated with the shared training data 106; etc.). In some instances, the authorization-aware training system 104 can receive or otherwise obtain the training data 102 in a mixed format, wherein one or more shared-access training examples are interleaved or otherwise combined with one or more private training examples. In some instances, the authorization-aware training system 104 can receive or otherwise obtain the training data 102 in a format that has already been separated based on access authorization data or is otherwise already separate from private and / or secure data 120. For example, in some instances the authorization-aware training system 104 can receive shared training data 106 from a first computing system and receive a set of private and / or secure data 120 from a second computing system. As outlined above, the second computing system may store the private and / or secure data 120 in a secure manner using one or more appropriate security protocols to prevent unauthorized access to the data 120. In such instances, the authorization-aware training system 104 can load the shared training data 106 in a format in which it was received, either with or without checking access authorization data associated w ith each training example.

[0061] The first machine-learned model 112 can include one or more machine- learned models. The first machine-learned model 112 can include various model architectures. An example model architecture for first machine-learned model 112 can include a neural network architecture (e.g., transformer, recurrent neural network, long shortterm memory', convolutional neural network, etc.). In some instances, the first machine- learned model 112 can include one or more machine-learned model architectures further described below with respect to Figures 8-17.

[0062] Training outputs 114 can generally include or otherwise represent various ty pes of data. Training outputs 114 can include one type or many different types of data. Training outputs 114 can be data of the same type(s) or of different types of data as compared to shared training data 106. Training outputs 114 can include one type or many different ty pes of data.

[0063] The model updates 116 can include updates to one or more parameters of the first machine-learned model 112. For example, the model update(s) 1 16 can include updating one or more parameters of the first machine-learned model 112 to optimize a value of an objective (e.g., loss function).

[0064] In some instances, the first machine-learned model 112 can be trained solely using the shared training data 106. without having access to any’ other training examples during training. For example, after the first machine-learned model 112 has generated training outputs 114 and received model updates 116 based on the shared training data 106, one or more parameters of the first machine-learned model 112 can be frozen, such that the first machine-learned model 112 is not subjected to any additional model updates 116. In other instances, the first machine-learned model 1 12 may be further trained (e.g.. continuously trained during deployment) based on data having a similar (e.g., same) access authorization profile compared to the shared training data 106.

[0065] Figure 1 depicts the second machine-learned model 122 obtaining pretrained initial parameters 118 from the first machine-learned model 112. The pretrained initial parameters 1 18 can comprise, for example, one or more parameters configured to initialize an initial state of the second machine-learned model 122 before training (e.g., via model updates 126). In some instances, the pretrained initial parameters 118 can be parameters of the first machine-learned model 112 learned during training of the first machine-learned model 112 (e.g., via model updates 116). The pretrained initial parameters 118 can comprise, for example, one or more parameter values of the first machine-learned model 112 after the first machine-learned model is fully or partially trained (e.g., using shared training data 106). In some instances, the first machine-learned model can have an architecture characterized by a plurality of layers, and the second machine-learned model can have an architecture comprising some or all of the layers of the first machine-learned model. In such instances, the pretrained initial parameters 118 can comprise parameters (e.g., weight, bias, etc.) associated with one or more layers shared by the first machine-learned model 112 and second machine- learned model 122.

[0066] The private and / or secure training data 120 can include, for example, data configured for access by one or more entities, wherein at least one entity authorized to access the shared training data 106 is not authorized to access the private and / or secure training data 120. Private and / or secure training data 120 can generally include or otherwise represent various ty pes of data. Private and / or secure training data 120 can include one type or many- different types of data. In some instances, private and / or secure training data 120 can comprise a plurality of training examples. In some instances, each training example of the private and / or secure training data 120 can be a training example of the training data 102. In some instances, each training example of the private and / or secure training data 120 can be associated with access authorization data indicating that one or more respective entities (e.g., users, accounts, organizations, computing systems, etc.) are authorized to access the training example. In some instances, the private and / or secure training data 120 can be associated with one or more full-private-access entities, wherein each entity- of the full-private-access entities is authorized to access every training example of the private and / or secure training data 120. In some instances, the private and / or secure training data 120 can comprise every training example of the training data 102 that is accessible to every entity of the full-private-access entities for the private and / or secure training data 120. In some instances, one or more full- shared-access entities for the shared training data 106 can lack authorization to access one or more training examples of the private and / or secure training data 120.

[0067] The second machine-learned model 122 can include one or more machine- learned models. The second machine-learned model 122 can include various model architectures. An example model architecture for second machine-learned model 122 can include a neural network architecture (e.g., transformer, recurrent neural network, long shortterm memory-, convolutional neural network, etc.). In some instances, the second machine- learned model 122 can include one or more machine-learned model architectures further described below with respect to Figures 8-17.

[0068] In some instances, an architecture of the second machine-learned model 122 can comprise an architecture of the first machine-learned model 112 (e.g., initialized with the pretrained initial parameters 118) along with one or more additional parameters (e.g., additional layers, weight modification parameters, etc.). In some instances, the second machine-learned model can be initially configured to generate outputs similar to (e.g., same as) values generated by the first machine-learned model 112 on similar inputs. For example, the one or more additional parameters can be initially configured to output values similar to (e.g., same as) values received as input, such that a combination of the pretrained initialparameters 118 and the one or more additional parameters is initially equivalent to an architecture of the first machine-learned model 112. In some instances, the one or more additional parameters can comprise, for example, one or more additional layers (e.g., between two layers of the first machine-learned model 112). In some instances, the one or more additional parameters can comprise one or more parameters for modifying (e.g., adding / subtracting, multiplying / dividing, etc.) one or more parameters of the first machine- learned model 112. For example, in some instances, second machine-learned model 122 can be configured to add the one or more additional parameters to one or more parameters of the first machine-learned model 112 before performing inference. In some instances, the second machine-learned model 122 and model updates 126 can be configured for any appropriate fine-tuning method (e.g.. adapter-based fine-tuning, low-rank adaptation, etc.) or other training method without going outside the scope of the present disclosure.

[0069] Training outputs 124 can generally include or otherwise represent various types of data. Training outputs 124 can include one type or many different types of data. Training outputs 124 can be data of the same type(s) or of different types of data as compared to private training data 120. Training outputs 124 can include one type or many different types of data.

[0070] The model updates 126 can include updates to one or more parameters of the second machine-learned model 122. For example, the model update(s) 126 can include updating one or more parameters of the second machine-learned model 122 to optimize a value of an objective (e g., loss function).

[0071] In some instances where an architecture of the second machine-learned model 122 comprises an architecture of the first machine-learned model 112 and one or more additional parameters, a model update 126 can comprise or consist of, for example, updating the one or more additional parameters without updating any parameters inherited from the first machine-learned model 112. In such instances, the second machine-learned model 122 can be stored as a standalone model after training, or the one or more additional parameters can be stored for use in combination with the first machine-learned model 112.

[0072] Although Figure 1 depicts only two machine-learned models 112. 122, a similar (e.g., same) process can be used to train additional (e.g., third, fourth, Nth, etc.) machine-learned models using additional sets of private and / or secure training data, which can be subsets of the training data 102 with properties similar to (e.g., same as) private and / or secure training data 120. In some instances, each additional set of private and / or secure training data can be associated with a unique set of full-private-access entities, which can bedifferent from the set of full-private-access entities for the private and / or secure training data 120. Additionally, although Figure 1 depicts one set of shared training data 106 and one set of private and / or secure training data 120, one or more subsets of the training data 102 can in some instances be both shared and private, meaning that a plurality of entities may share access to the one or more subsets, while one or more other entities may lack authorization to access the one or more subsets. For example, in some instances a first machine-learned model can be trained using a public dataset accessible to every member of the general public; a second machine-learned model can be trained using data accessible only to a first plurality of entities (e.g., members of an organization or group) and inaccessible to at least one member of the general public; and a third machine-learned model can be trained using data accessible only to a second plurality of entities different from the first plurality of entities. In some instances, the second plurality of entities can overlap with, be a subset of, or be disjoint from the first plurality of entities. A security level associated with the data accessible to only the first plurality of entities may be different from a security level associated with the public dataset. Additionally, the security level(s) associated with one or both of these datasets may be different from a security level associated with the data accessible to only the second plurality of entities.

[0073] In some instances, a first plurality of users authorized to access the private and / or secure training data 120 may be a superset of a second plurality of users authorized to access an additional set of private and / or secure training data. In such instances, a third machine-learned model can be fine-tuned based on the additional set of private and / or secure training data and the second machine-learned model 122. In some instances, this fine-tuning can be performed by retaining a first plurality of additional parameters associated with the second machine-learned model 122 and adding a second plurality of additional parameters associated with the third machine-learned model.

[0074] Figure 2 is a block diagram of an example computing system according to the present disclosure, wherein a single inference endpoint can provide authorization-aware inference for a plurality of users having a plurality of different access authorizations. A requester 202 can provide an inference request 204 to an authorization-based inference router 206. Based on access authorization data associated with the requester 202, the authorizationbased inference router 206 can select a machine-learned model from a plurality of machine- learned models 112, 122, 224. The authorization-based inference router 206 can provide a routed inference request 208 to the selected machine-learned model (e.g.. Nth machine- learned model 224), and the selected machine-learned model can provide an inference output210 to the authorization-based inference router 206. The authorization-based inference router 206 can relay the inference output 210 to the requester 202.

[0075] The requester 202 can include, for example, any entity capable of submitting an inference request (e.g. user; computing system; service account; organization; etc.). In some instances, the requester 202 can have, be associated with, or be characterized by one or more access authorizations indicative of data the requester 202 is authorized to access.

[0076] An inference request 204 can generally include or otherwise represent various types of data. An inference request 204 can include one ty pe or many different ty pes of data. In some instances, an inference request 204 can be received from the requester 202 through one or more inference endpoints (e.g., APIs, user interfaces such as GUIs, etc.). In some instances, a single inference endpoint can be configured to receive inference requests 204 from a plurality of requesters 202 having a plurality of different data access authorizations. In some instances, an inference request can include, be associated with, or be characterized by access authorization data indicative of the requester 202’s authorization to access one or more data items. In some instances, access authorization data can include, for example, an API key, username, password, two-factor authentication data, security certificate data. etc. In some instances, access authorization data can include identitying information (e g., IP address, MAC address, username, etc) associated with the requester 202 or a device of the requester 202. In some instances, identifying information of the requester 202 can be compared to identifying information associated with one or more entities authorized to access one or more machine-learned models 1 12, 122, 224. In some instances, access authorization data can include other relevant information (e.g., geolocation data, etc.) associated with the requester 202 or a device of the requester 202, w hich can in some instances be used to confirm or disconfirm other access authorization data (e.g.. identifying information).

[0077] Access authorization data can include or otherwise be based on various access restrictions. For example, access authorization data can include or be based on one or more legal restrictions (e.g., contractual restrictions, data ownership rules, data privacy restrictions, etc.) governing data access. In some instances, access authorization data can include one or more rules defined by a data owner associated with one or more data sets. For example, a data owner (e.g., an individual) may in some instances authorize one or more other entities (e.g., doctors, employers or employees, family, friends, the general public, etc.) to access one or more of the data owner's private data examples or data sets (e.g., Google Photo album, etc.). In some instances, an organizational data owner may authorize data access based on one or more organizational roles (e.g., professional engineering or medical roles where access tosecure and / or private data is required to perform the role, vs roles where such access is not required to perform the role, etc.).

[0078] In some instances, access authorization data can indicate, either expressly or implicitly, that a particular entity (e.g., person, organization, computing system, etc.) is authorized to access one or more data items. In some instances, access authorization data can indicate, either expressly or implicitly, that a particular entity is not authorized to access one or more data items. For example, in some instances, access authorization data can include an access control list expressly identifying one or more entities that are authorized to access one or more data items. For example, an access control list can include any appropriate identifying information (e.g., IP address, username, security certificate information, biometric data, etc.) associated with one or more entities authorized to access data subject to the access control list. In some instances, an access control list can be configured to expressly identify all entities authorized to access data subject to the access control list. In such instances, an access control list can indicate, for every unlisted entity that is not expressly identified by the access control list as an authorized entity, that the unlisted entity is not authorized to access data subject to the access control list. Similarly, in some instances, an access control list can identify, for a particular entity, one or more (e.g., all) data items the entity is authorized to access. In such instances, an access control list or plurality of access control lists associated with an entity can indicate, for each unlisted data item not included on the access control list(s), that the entity is not authorized to access the unlisted data item.

[0079] In some instances, a lack of access authorization data can indicate that an entity7is not authorized to access one or more data items. For example, in some instances, an authorization-based inference router 206 may lack sufficient identifying information or authenticating information to satisfy a data security protocol. In such instances, a lack of sufficient access authorization data can indicate that a requester 202 is not authorized to access one or more data items. As a non-limiting illustrative example, an authorization-based inference router 206 may receive an inference request 204 comprising a username and password appearing to identify a requester 202 as an entity that can be authorized to access a data item upon compliance with a specified data security protocol. In response, the authorization-based inference router 206 may request further identifying or authenticating information, such as a multi-factor authentication action in compliance with the data security' protocol, to enable the requester 202 to gain access authorization under the data security protocol. If a requester 202 fails to provide further access authorization data as requested, then the lack of further access authorization data sufficient to satisfy the data securityprotocol can indicate that the requester 202 is not authorized to access the data at the time of the inference request 204.

[0080] In some instances, a single requester 202 can be authorized to access a plurality of private and / or secure datasets or machine-learned models 1 12, 122, 224. For example, an organizational data owner may authorize an individual having tw o or more roles (e.g., engineering team leader) to access two or more private and / or secure data sets (e.g., engineering dataset, team leader dataset, etc.). As another example, a plurality of respective individual data owners may each authorize a single entity (e.g., friend, family member) to access a respective private dataset, such that the entity may have access authorization for a plurality of disjoint datasets owned by a plurality of unrelated owners. Example systems for inference when a requester 202 is authorized to access a plurality of machine-learned models 112, 122, 224 are further described below with respect to Figure 4.

[0081] The authorization-based inference router 206 can comprise, for example, one or more computing devices. The authorization-based inference router 206 can be or include one or more software, firmware, or hardware components configured to process an inference request 204 based on access authonzations associated with the inference request 204. In some instances, a computing device or component can comprise one or more computing devices or components described with respect to Figures 15-17.

[0082] Figure 2 depicts the authorization-based inference router 206 routing the inference request 204 to a selected machine-learned model 112. 122, 224 based on access authorization data associated with the requester 202 or the inference request 204. For example, the authorization-based inference router 206 can compare access authorization data associated with the requester 202 to one or more access authorization requirements associated with one or more machine-learned models 112, 122, 224. Access authorization requirements can be configured, for example, to ensure that a requester 202 cannot receive an inference output 210 from a machine-learned model 112, 122, 224 whose training dataset includes data that exceeds the requester’s data access authorizations. The authorization-based inference router 206 can determine, for example, which machine-learned models 112, 122, 224 have access authorization requirements that are met or not met by the requester 202. If a requester meets the access authorization requirements of exactly one machine-learned model, the authorization-based inference router 206 can route the inference request 204 to that model. If a requester does not meet the access authorization requirements of any machine-learned models, the authorization-based inference router 206 can deny the inference request 204. If a requester meets the access authorization requirements of more than one machine-learnedmodel 112, 122, 224, then the authorization-based inference router 206 can, for example, select a machine-learned model 112. 122, 224 according to one or more preference criteria (e.g., the authorized model trained on the most training data) or according to another selection process (e.g., offering the requester 202 an option to select a preferred model). Additional example implementations for routing inference requests 204 from requesters 202 with multi-model access are further described below with respect to Figure 4.

[0083] In some instances, routing the inference request 204 can include or not include one or more actions to verify access authorization data of a requester 202 or inference request 204. For example, in some instances an inference request 204 may contain secure or reliable data indicative of authorization to access a particular machine-learned model 112, 122. 224 (e.g., private API key, password, cryptographic data, etc.); in such instances, an authorization-based inference router 206 can route the inference request 204 based on the reliable data. In some instances, the authorization-based inference router 206 can request additional access authorization data (e.g., to verify access authorization data already received) before routing an inference request 204. For example, in some instances, a username may identify a requester 202 as an authorized entity for a particular machine-learned model 112, 122, 224. In such instances, an authorization-based inference router 206 may ask the requester 202 to perform an action to verify' their identity. For example, in some instances an authorization-based inference router 206 may ask a requester 202 to reenter a password or perform a two-factor authentication action such as entering a verification code or approving a push notification. In some instances, an authentication protocol of the authorization-based inference router 206 can include steps for verifying identify information based on other relevant information. For example, if an inference request 204 is associated with a username, geolocation data associated with the inference request 204 can be compared to past geolocation data associated with the username. For example, if a requester 202 is determined to be in a similar location (e.g., same building, etc.) compared to past inference requests 204 associated with the username, then the authorization-based inference router 206 can in some instances route an inference request 204 without further verification. As another example, if a requester 202 is determined to be in a different location (e.g.. different country) compared to past inference requests 204 associated with the username, then the authorization-based inference router 206 can perform additional verification steps (e.g., two-factor authentication).

[0084] A routed inference can be, comprise, be comprised by, or otherwise share one or more properties with an inference request 204. In some instances, a routed inferencerequest 208 can comprise all or part of an inference request 204, along with additional information (e.g., routing information or model selection information).

[0085] An inference output 210 can generally include or otherwise represent various types of data. An inference output 210 can include one type or many different types of data. An inference output 210 can comprise data of the same type(s) or of different types of data as compared to an inference request 204.

[0086] The Nth machine-learned model 224 can include one or more machine-learned models. The Nth machine-learned model 224 can include various model architectures. An example model architecture for Nth machine-learned model 224 can include a neural network architecture (e.g., transformer, recurrent neural network, long short-term memory, convolutional neural network, etc.). In some instances, the Nth machine-learned model can be a model that was trained in a manner similar to (e.g., same as) a manner of training the second machine-learned model 122 (e.g., using a subset of private data other than the private data 120 used to train the second machine-learned model 122). In some instances, the Nth machine-learned model 224 can include one or more machine-learned model architectures further described below with respect to Figures 8-17.

[0087] Figure 3 is a block diagram of an example computing system according to the present disclosure, wherein an inference endpoint can store and serve a plurality7of machine- learned models trained on a dataset characterized by an access level hierarchy. A first machine-learned model 112 can be a model that was trained on shared or public data (e.g.. shared data 106). A second machine-learned model 122 can be a model that was trained based on a first machine-learned model 112 and a first plurality of private training examples (e.g., private and / or secure data 120). A third machine-learned model 332 can be a model that was trained based on the second machine-learned model and a second plurality of private and / or secure training examples. In some instances, access authorizations of the first and second pluralities can be hierarchical, such that every entity' having full access to the second plurality' of private training examples can also have full access to the first plurality of training examples.

[0088] Figure 3 depicts the second machine-learned model 122 comprising a plurality of parameters inherited from the first machine-learned model 112 (e g., all parameters of the first machine-learned model 112) and a plurality of first adapter parameters 330. In some instances, the first adapter parameters 330 can comprise one or more layers of the second machine-learned model 122 (e.g., configured to be inserted between layers of the first machine-learned model). In some instances, the first adapter parameters 330 can compriseone or more parameters (e.g., rank decomposition matrices, etc.) for modifying (e.g., adding / subtracting, multiply ing / dividing, etc.) one or more parameters (e.g., weights) of the first machine-learned model 112. In some instances, the second machine-learned model 122 can be stored as a standalone model (e.g., storing parameters inherited from the first machine- learned model 112 interleaved with first adapter parameters 330 in a single combined model; storing modified parameters computed by using first adapter parameters 330 to modify parameters of the first machine-learned model 1 12; etc.). In other instances, the first adapter parameters 330 can be stored separately, to be used in combination with the first machine- learned model 112.

[0089] Figure 3 depicts a third machine-learned model 332. The third machine- learned model 332 can include various model architectures. An example model architecture for third machine-learned model 332 include a neural network architecture (e.g., transformer, recurrent neural network, long short-term memory', convolutional neural network, etc.). In some instances, the third machine-learned model 332 can be a model that was trained in a manner similar to (e.g., same as) a manner of training the second machine-learned model 122 (e.g.. in a manner described with respect to Figure 1).

[0090] Figure 3 depicts the third machine-learned model 332 comprising a plurality of parameters inherited from the second machine-learned model 122 (e.g., all parameters of the second machine-learned model 122) and a plurality of second adapter parameters 334. In some instances, the second adapter parameters 334 can comprise one or more layers of the third machine-learned model 332 (e.g., configured to be inserted between layers of the first machine-learned model). In some instances, the second adapter parameters 334 can comprise one or more parameters (e.g., rank decomposition matrices, etc.) for modifying (e.g., adding / subtracting, multiply ing / dividing, etc.) one or more parameters (e.g., weights) of the second machine-learned model 122. In some instances, the third machine-learned model 332 can be stored as a standalone model (e.g., storing parameters inherited from the second machine-learned model 122 interleaved with second adapter parameters 334 in a single combined model; storing modified parameters computed by using second adapter parameters 334 to modify parameters of the second machine-learned model 122; etc.). In other instances, the second adapter parameters 334 can be stored separately, to be used in combination with, for example, the first machine-learned model 112 and the first adapter parameters 330.

[0091] Figure 4 is a block diagram of an example computing system according to the present disclosure, wherein an inference endpoint can route an inference request to more than one machine-learned model. A requester 202 may have access authorization, for example, totwo or more sets (e.g., disjoint sets) of private and / or secure training data. In such instances, the authorization-based inference router 206 can select two or more machine-learned models 122, 224 to use for inference, wherein each of the selected machine-learned models can be a model that was trained on one of the two or more sets of private and / or secure training data. The authorization-based inference router 206 can provide a routed inference request 208 to the selected machine-learned models, and the selected machine-learned models can each provide an inference output 210 to the authorization-based inference router 206. The authorization-based inference router 206 can relay the inference outputs 210 to an output reconciler, which can combine or otherwise reconcile the inference outputs 210 to generate a reconciled output 442, which can be provided to the requester 202.

[0092] In some instances, an authorization-based inference router 206 can include one or more machine-learned models. For example, in some instances, an inference request 204 may include a “multi-hop” inference request having two or more logical components. For example, “What is the birth date of the patient booked into surgery today?” may require identifying the relevant patient before determining that patient's birth date. As another example. “Do any of the process engineers on the Tulsa project have a U.S. government security clearance of ‘confidential’ or higher?” may require identifying the relevant process engineers before determining their security clearances. In some instances, an inference request 204 may comprise or otherwise depend on a first inference component that is best generated by one machine-learned model 112. 122, 224, and a second inference component that is best generated by a different machine-learned model 1 12, 122, 224. In some instances, generating a routed inference request 208 can comprise, for example, using a machine- learned model to decompose or otherw ise modify an inference request 204 based on one or more data properties (e.g., data category, etc.) of the training data that was used to train a selected machine-learned model 122, 224.

[0093] The output reconciler 440 can be, comprise, or be implemented by, for example, one or more computing devices. The output reconciler 440 can be or include one or more software, firmware, or hardw are components configured to process a plurality of inference outputs 210 to generate a single reconciled output 442. In some instances, the output reconciler can be implemented by a computing system that is the same as or different from a computing system associated with the authorization-based inference router. In some instances, a computing device or component can comprise one or more computing devices or components described with respect to Figures 15-17.

[0094] A reconciled output 442 can generally include or otherwise represent various types of data. A reconciled output 442 can include one type or many different types of data. A reconciled output 442 can comprise data of the same type(s) or of different types of data as compared to an inference output 210.

[0095] Generating a reconciled output 442 can comprise, for example, combining two or more inference outputs 210 or generating a new output based on the two or more outputs. In some instances, generating a reconciled output 442 can comprise concatenating two or more inference outputs 210, such that the requester 202 receives a plurality of inference outputs 210. In some instances, generating a reconciled output can comprise machine-learned reconciliation. For example, in instances where two or more inference outputs 210 comprise sequence outputs (e.g.. text, image, audio, etc.), reconciling the inference outputs 210 can comprise prompting a machine-learned sequence processing model with the two or more inference outputs 210. In some instances, a machine-learned sequence processing model (e.g., language model) can also be prompted with one or more instructions for reconciling the two or more inference outputs 210 (e.g., “please summarize the following:'; “please combine the following answers into a single coherent answer:”, “If the following answers are inconsistent with each other, please point out and explain the inconsistencies:”, etc ).

[0096] In some instances, reconciling inference outputs 210 can comprise one or more mathematical operations. For example, in some instances inference outputs 210 may comprise one or more probabilities (e.g., a confidence level associated with a classification output, a probability distribution associated with a sequence generation output, etc.) or other numerical values. In some instances, such inference outputs 210 can be combined through mathematical combination (e.g., averaging, weighted averaging, median / mode. etc ). In some instances, a mathematical combination can include a weighted average, wherein a weight of the weighted average can be based on, for example, a number of private training examples used to train the selected machine-learned models; a number of relevant training examples (e.g., according to a machine-learned estimate of relevance generated by the selected machine-learned models 122, 224); a confidence level associated with the inference output 210; etc.Example Methods

[0097] Figure 5 depicts a flowchart diagram of an example method for authorization- aware training of one or more machine-learned models according to example embodiments of the present disclosure. Although Figure 5 depicts steps performed in a particular order forpurposes of illustration and discussion, the methods of the present disclosure are not limited to the particularly illustrated order or arrangement. The various steps of example method 500 can be omitted, rearranged, combined, and / or adapted in various ways without deviating from the scope of the present disclosure.

[0098] At 502, example method 500 can include obtaining, by one or more computing devices, a training dataset comprising a plurality of data items. In some instances, a training dataset can be. comprise, or be comprised by training data 102. In some instances, example method 500 at 502 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0099] At 504, example method 500 can include obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item. In some instances, example method 500 at 504 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0100] At 506, example method 500 can include determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset, wherein the access authorization data indicates that a first entity is authorized to access each data item of the first subset, and wherein the access authorization data indicates that a second entity is authorized to access each data item of the first subset. In some instances, a first subset can be, comprise, or be comprised by shared training data 106. In some instances, example method 500 at 506 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0101] At 508, example method 500 can include determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset, wherein the access authorization data indicates that the first entity is authorized to access each data item of the second subset, and wherein the access authorization data indicates that the second entity is not authorized to access at least one data item of the second subset. In some instances, a second subset can be, comprise, or be comprised by private and / or secure training data 120. In some instances, example method 500 at 508 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0102] At 510, example method 500 can include training, by the one or more computing devices based on the first subset, a first machine-learned model. In some instances, a first machine-learned model can be, comprise, or be comprised by a firstmachine-learned model 112. In some instances, example method 500 at 510 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0103] At 512, example method 500 can include training, by the one or more computing devices based on the first machine-learned model and the second subset, a second machine-learned model. In some instances, a second machine-learned model can be, comprise, or be comprised by a second machine-learned model 122. In some instances, example method 500 at 512 can include using one or more systems or performing one or more activities described with respect to Figure 1.

[0104] Figure 6 depicts a flowchart diagram of an example method for authorization- aware inference routing according to example embodiments of the present disclosure. Although Figure 6 depicts steps performed in a particular order for purposes of illustration and discussion, the methods of the present disclosure are not limited to the particularly illustrated order or arrangement. The various steps of example method 600 can be omitted, rearranged, combined, and / or adapted in various ways without deviating from the scope of the present disclosure.

[0105] At 602, example method 600 can include receiving, by one or more computing devices, an inference request from a requester. In some instances, a requester can be, comprise, or be comprised by a requester 202. In some instances, an inference request can be, comprise, or be comprised by an inference request 204. In some instances, example method 600 at 602 can include using one or more systems or performing one or more activities described with respect to Figures 2-4.

[0106] At 604, example method 600 can include obtaining, by the one or more computing devices, access authorization data indicating that the requester is authorized to access one or more first data items and that the requester is not authorized to access one or more second data items. In some instances, example method 600 at 604 can include using one or more systems or performing one or more activities described with respect to Figures 2-4.

[0107] At 606, example method 600 can include obtaining, by the one or more computing devices, a plurality of respective machine-learned models trained using a plurality of respective datasets. In some instances, example method 600 at 606 can include using one or more systems or performing one or more activities described with respect to Figures 2-4.

[0108] At 608, example method 600 can include selecting, by the one or more computing devices based on the access authorization data, a machine-learned model of the plurality of machine-learned models. In some instances, example method 600 at 608 caninclude using one or more systems or performing one or more activities described with respect to Figures 2-4.

[0109] At 610, example method 600 can include generating, by the one or more computing devices using the machine-learned model based on the inference request, an output. In some instances, an output can be, comprise, or be comprised by an inference output 210 or reconciled output 442. In some instances, example method 600 at 610 can include one or more steps described with respect to Figures 2-4.

[0110] At 612, example method 600 can include providing, by the one or more computing devices, the output to the requester. In some instances, example method 600 at 612 can include using one or more systems or performing one or more activities described with respect to Figures 2-4.

[0111] Figure 7 depicts a flowchart diagram of an example method for multi-model authorization-aware inference according to example embodiments of the present disclosure. Although Figure 7 depicts steps performed in a particular order for purposes of illustration and discussion, the methods of the present disclosure are not limited to the particularly illustrated order or arrangement. The various steps of example method 700 can be omitted, rearranged, combined, and / or adapted in various ways without deviating from the scope of the present disclosure.

[0112] At 702, example method 700 can include receiving, by one or more computing devices, an inference request from a requester. In some instances, a requester can be. comprise, or be comprised by a requester 202. In some instances, an inference request can be, comprise, or be comprised by an inference request 204. In some instances, example method 700 at 702 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0113] At 704, example method 700 can include obtaining, by the one or more computing devices, access authorization data indicating that the requester is authorized to access one or more first data items and that the requester is not authorized to access one or more second data items. In some instances, example method 700 at 704 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0114] At 706, example method 700 can include obtaining, by the one or more computing devices, a plurality of respective machine-learned models trained using a plurality of respective datasets. In some instances, example method 700 at 706 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0115] At 708, example method 700 can include selecting, by the one or more computing devices based on the access authorization data, a first selected machine-learned model of the plurality of machine-learned models. In some instances, example method 700 at 708 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0116] At 710, example method 700 can include selecting, by the one or more computing devices based on the access authorization data, an additional machine-learned model of the plurality of machine-learned models. In some instances, example method 700 at 710 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0117] At 712, example method 700 can include generating, by the one or more computing devices using the first selected machine-learned model based on the inference request, a first inference. In some instances, a first inference can be, comprise, or be comprised by an inference output 210. In some instances, example method 700 at 712 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0118] At 714, example method 700 can include generating, by the one or more computing devices using the additional machine-learned model based on the inference request, a second inference. In some instances, a second inference can be, comprise, or be comprised by an inference output 210. In some instances, example method 700 at 714 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0119] At 716, example method 700 can include generating, by the one or more computing devices based on the first inference and second inference, an output. In some instances, an output can be, comprise, or be comprised by a reconciled output 442. In some instances, example method 700 at 716 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0120] At 718, example method 700 can include providing, by the one or more computing devices, the output to the requester. In some instances, example method 700 at 718 can include using one or more systems or performing one or more activities described with respect to Figure 4.

[0121] Figure 8 depicts a flowchart of a method 800 for training one or more machine-learned models according to aspects of the present disclosure. For instance, anexample machine-learned model can include a first machine-learned model 112, second machine-learned model 122. or Nth machine-learned model 224.

[0122] One or more portion(s) of example method 800 can be implemented by a computing system that includes one or more computing devices such as, for example, computing systems described with reference to the other figures. Each respective portion of example method 800 can be performed by any (or any combination) of one or more computing devices. Moreover, one or more portion(s) of example method 800 can be implemented on the hardware components of the device(s) described herein, for example, to train one or more systems or models. Figure 8 depicts elements performed in a particular order for purposes of illustration and discussion. Those of ordinary skill in the art, using the disclosures provided herein, will understand that the elements of any of the methods discussed herein can be adapted, rearranged, expanded, omitted, combined, or modified in various ways without deviating from the scope of the present disclosure. Figure 8 is described with reference to elements / terms described with respect to other systems and figures for exemplary illustrated purposes and is not meant to be limiting. One or more portions of example method 800 can be performed additionally, or alternatively, by other systems.

[0123] At 802, example method 800 can include obtaining a training instance. A set of training data can include a plurality of training instances divided between multiple datasets (e.g., a training dataset, a validation dataset, or testing dataset). A training instance can be labeled or unlabeled. Although referred to in example method 800 as a “training’7instance, it is to be understood that runtime inferences can form training instances when a model is trained using an evaluation of the model’s performance on that runtime instance (e.g., online training / leaming). Example data ty pes for the training instance and various tasks associated therewith are described throughout the present disclosure.

[0124] At 804, example method 800 can include processing, using one or more machine-learned models, the training instance to generate an output. The output can be directly obtained from the one or more machine-learned models or can be a downstream result of a chain of processing operations that includes an output of the one or more machine- learned models.

[0125] At 806, example method 800 can include receiving an evaluation signal associated with the output. The evaluation signal can be obtained using a loss function. Various determinations of loss can be used, such as mean squared error, likelihood loss, cross entropy loss, hinge loss, contrastive loss, or various other loss functions. The evaluation signal can be computed using known ground-truth labels (e.g., supervised learning), predictedor estimated labels (e.g., semi- or self-supervised learning), or without labels (e.g., unsupervised learning). The evaluation signal can be a reward (e.g., for reinforcement learning). The reward can be computed using a machine-learned reward model configured to generate rewards based on output(s) received. The reward can be computed using feedback data describing human feedback on the output(s).

[0126] At 808, example method 800 can include updating the machine-learned model using the evaluation signal. For example, values for parameters of the machine-learned model(s) can be learned, in some embodiments, using various training or learning techniques, such as, for example, backwards propagation. For example, the evaluation signal can be backpropagated from the output (or another source of the evaluation signal) through the machine-learned model(s) to update one or more parameters of the model(s) (e.g., based on a gradient of the evaluation signal with respect to the parameter value(s)). For example, system(s) containing one or more machine-learned models can be trained in an end-to-end manner. Gradient descent techniques can be used to iteratively update the parameters over a number of training iterations. In some implementations, performing backwards propagation of errors can include performing truncated backpropagation through time. Example method 800 can include implementing a number of generalization techniques (e g., w eight decays, dropouts, etc.) to improve the generalization capability of the models being trained.

[0127] In some implementations, example method 800 can be implemented for training a machine-learned model from an initialized state to a fully trained state (e.g., when the model exhibits a desired performance profile, such as based on accuracy, precision, recall, etc.).

[0128] In some implementations, example method 800 can be implemented for particular stages of a training procedure. For instance, in some implementations, example method 800 can be implemented for pre-training a machine-learned model. Pre-training can include, for instance, large-scale training over potentially noisy data to achieve a broad base of performance levels across a variety of tasks / data types. In some implementations, example method 800 can be implemented for fine-tuning a machine-learned model. Fine-tuning can include, for instance, smaller-scale training on higher-quality (e.g.. labeled, curated, etc.) data. Fine-tuning can affect all or a portion of the parameters of a machine-learned model. For example, various portions of the machine-learned model can be “frozen” for certain training stages. For example, parameters associated with an embedding space can be “frozen” during fine-tuning (e.g., to retain information learned from a broader domain(s) than present in the fine-tuning dataset(s)). An example fine-tuning approach includes reinforcementlearning. Reinforcement learning can be based on user feedback on model performance during use.Example Machine-Learned Models

[0129] Figure 9 is a block diagram of an example processing flow for using machine- learned model(s) 1 to process input(s) 2 to generate output(s) 3.

[0130] Machine-learned model(s) 1 can be or include one or multiple machine- learned models or model components. Example machine-learned models can include neural networks (e.g., deep neural networks). Example machine-learned models can include nonlinear models or linear models. Example machine-learned models can use other architectures in lieu of or in addition to neural networks. Example machine-learned models can include decision tree based models, support vector machines, hidden Markov models, Bayesian networks, linear regression models, k-means clustering models, etc.

[0131] Example neural networks can include feed-forward neural networks, recurrent neural networks (RNNs), including long short-term memory (LSTM) based recurrent neural networks, convolutional neural networks (CNNs), diffusion models, generative-adversarial networks, or other forms of neural networks. Example neural networks can be deep neural networks. Some example machine-learned models can leverage an attention mechanism such as self-attention. For example, some example machine-learned models can include multiheaded self-attention models.

[0132] Machine-learned model(s) 1 can include a single or multiple instances of the same model configured to operate on data from input(s) 2. Machine-learned model(s) 1 can include an ensemble of different models that can cooperatively interact to process data from input(s) 2. For example, machine-learned model(s) 1 can employ a mixture-of-experts structure. See. e.g., Zhou et al., Mixture-of-Experts with Expert Choice Routing, ARXIV:2202.09368V2 (Oct. 14, 2022).

[0133] Input(s) 2 can generally include or otherwise represent various types of data. Input(s) 2 can include one type or many different types of data. Output(s) 3 can be data of the same type(s) or of different types of data as compared to input(s) 2. Output(s) 3 can include one type or many different types of data.

[0134] Example data pes for input(s) 2 or output(s) 3 include natural language text data, software code data (e.g., source code, object code, machine code, or any other form of computer-readable instructions or programming languages), machine code data (e.g.. binary code, assembly code, or other forms of machine-readable instructions that can be executeddirectly by a computer's central processing unit), assembly code data (e.g., low-level programming languages that use symbolic representations of machine code instructions to program a processing unit), genetic data or other chemical or biochemical data, image data, audio data, audiovisual data, haptic data, biometric data, medical data, financial data, statistical data, geographical data, astronomical data, historical data, sensor data generally (e.g., digital or analog values, such as voltage or other absolute or relative level measurement values from a real or artificial input, such as from an audio sensor, light sensor, displacement sensor, etc.), and the like. Data can be raw or processed and can be in any format or schema.

[0135] In multimodal inputs 2 or outputs 3, example combinations of data types include image data and audio data, image data and natural language data, natural language data and software code data, image data and biometric data, sensor data and medical data, etc. It is to be understood that any combination of data types in an input 2 or an output 3 can be present.

[0136] An example input 2 can include one or multiple data t pes, such as the example data types noted above. An example output 3 can include one or multiple data types, such as the example data types noted above. The data type(s) of input 2 can be the same as or different from the data t pe(s) of output 3. It is to be understood that the example data types noted above are provided for illustrative purposes only. Data types contemplated within the scope of the present disclosure are not limited to those examples noted above.Example Machine-Learned Sequence Processing Models

[0137] Figure 10 is a block diagram of an example implementation of an example machine-learned model configured to process sequences of information. For instance, an example implementation of machine-learned model(s) 1 can include machine-learned sequence processing model(s) 4. An example system can pass input(s) 2 to sequence processing model(s) 4. Sequence processing model(s) 4 can include one or more machine- learned components. Sequence processing model(s) 4 can process the data from input(s) 2 to obtain an input sequence 5. Input sequence 5 can include one or more input elements 5-1, 5- 2, . . . , 5-AT, etc. obtained from input(s) 2. Sequence processing model 4 can process input sequence 5 using prediction layer(s) 6 to generate an output sequence 7. Output sequence 7 can include one or more output elements 7-1, 7-2, . . . , 7-7V, etc. generated based on input sequence 5. The system can generate output(s) 3 based on output sequence 7.

[0138] Sequence processing model(s) 4 can include one or multiple machine-learned model components configured to ingest, generate, or otherwise reason over sequences ofinformation. For example, some example sequence processing models in the text domain are referred to as ‘"Large Language Models." or LLMs. See. e.g., PaLM 2 Technical Report, GOOGLE, https: / / ai.google / static / documents / palm2techreport.pdf (n.d.). Other example sequence processing models can operate in other domains, such as image domains, see, e.g., Dosovitskiy et al., An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale, ARXIV:2010. 11929V2 (Jun. 3. 2021), audio domains, see. e.g., Agostinelli et al., MusicLM: Generating Music From Text, ARXlV:2301.11325vl (Jan. 26, 2023), biochemical domains, see, e.g., Jumper et al., Highly accurate protein structure prediction with AlphaFold, 596 Nature 583 (Aug. 26, 2021), by way of example. Sequence processing model(s) 4 can process one or multiple types of data simultaneously. Sequence processing model(s) 4 can include relatively large models (e.g.. more parameters, computationally expensive, etc.), relatively small models (e.g., fewer parameters, computationally lightweight, etc.), or both.

[0139] In general, sequence processing model(s) 4 can obtain input sequence 5 using data from input(s) 2. For instance, input sequence 5 can include a representation of data from input(s) 2 in a format understood by sequence processing model(s) 4. One or more machine- learned components of sequence processing model(s) 4 can ingest the data from input(s) 2. parse the data into pieces compatible with the processing architectures of sequence processing model(s) 4 (e.g., via “tokenization"’), and project the pieces into an input space associated with prediction layer(s) 6 (e.g., via “embedding’").

[0140] Sequence processing model(s) 4 can ingest the data from input(s) 2 and parse the data into a sequence of elements to obtain input sequence 5. For example, a portion of input data from input(s) 2 can be broken dowor into pieces that collectively represent the content of the portion of the input data. The pieces can provide the elements of the sequence.

[0141] Elements 5-1, 5-2, . . . . 5-M can represent, in some cases, building blocks for capturing or expressing meaningful information in a particular data domain. For instance, the elements can describe “atomic units” across one or more domains. For example, for textual input source(s), the elements can correspond to groups of one or more w ords or sub-word components, such as sets of one or more characters.

[0142] For example, elements 5-1. 5-2, . . . . 5-M can represent tokens obtained using a tokenizer. For instance, a tokenizer can process a given portion of an input source and output a series of tokens (e.g., corresponding to input elements 5-1, 5-2, . . . , 5-M) that represent the portion of the input source. Various approaches to tokenization can be used. For instance, textual input source(s) can be tokenized using a byte-pair encoding (BPE) technique. See, e.g.. Kudo et al., SentencePiece: A simple and language independent subwordtokenizer and detokenizer for Neural Text Processing, PROCEEDINGS OF THE 2018 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING (System Demonstrations), pages 66-71 (October 31-November 4, 2018), https: / / aclanthology.org / D18-2012.pdf. Image-based input source(s) can be tokenized by extracting and serializing patches from an image.

[0143] In general, arbitrary’ data types can be serialized and processed into input sequence 5. It is to be understood that element(s) 5-1. 5-2, . . . . 5-M depicted in Figure 10 can be the tokens or can be the embedded representations thereof.

[0144] Prediction layer(s) 6 can predict one or more output elements 7-1, 7-2, . . . , 7- N based on the input elements. Prediction layer(s) 6 can include one or more machine-learned model architectures, such as one or more layers of learned parameters that manipulate and transform the input(s) to extract higher-order meaning from, and relationships between, input element(s) 5-1, 5-2, . . . , 5-M. In this manner, for instance, example prediction layer(s) 6 can predict new output element(s) in view of the context provided by input sequence 5.

[0145] Prediction layer(s) 6 can evaluate associations between portions of input sequence 5 and a particular output element. These associations can inform a prediction of the likelihood that a particular output follows the input context. For example, consider the textual snippet, “The carpenter’s toolbox was small and heavy. It was full of Example prediction layer(s) 6 can identify that “It” refers back to “toolbox” by determining a relationship between the respective embeddings. Example prediction layer(s) 6 can also link “It” to the attributes of the toolbox, such as “small” and “heavy .” Based on these associations, prediction layer(s) 6 can, for instance, assign a higher probability’ to the word “nails” than to the word “sawdust.”

[0146] A transformer is an example architecture that can be used in prediction layer(s) 4. See, e.g., Vaswani et al., Attention Is All You Need, ARXlV:1706.03762v7 (Aug. 2, 2023). A transformer is an example of a machine-learned model architecture that uses an attention mechanism to compute associations betw een items within a context w indow’. The context window can include a sequence that contains input sequence 5 and potentially one or more output element(s) 7-1, 7-2. . . . , 7-N. A transformer block can include one or more attention layer(s) and one or more post-attention layer(s) (e.g., feedforward layer(s), such as a multi-layer perceptron).

[0147] Prediction lay er(s) 6 can include other machine-learned model architectures in addition to or in lieu of transformer-based architectures. For example, recurrent neural networks (RNNs) and long short-term memory (LSTM) models can also be used, as well asconvolutional neural networks (CNNs). In general, prediction layer(s) 6 can leverage various kinds of artificial neural networks that can understand or generate sequences of information.

[0148] Output sequence 7 can include or otherwise represent the same or different data types as input sequence 5. For instance, input sequence 5 can represent textual data, and output sequence 7 can represent textual data. Input sequence 5 can represent image, audio, or audiovisual data, and output sequence 7 can represent textual data (e.g., describing the image, audio, or audiovisual data). It is to be understood that prediction layer(s) 6. and any other interstitial model components of sequence processing model(s) 4, can be configured to receive a variety of data types in input sequence(s) 5 and output a variety of data ty pes in output sequence(s) 7.

[0149] Output sequence 7 can have various relationships to input sequence 5. Output sequence 7 can be a continuation of input sequence 5. Output sequence 7 can be complementary to input sequence 5. Output sequence 7 can translate, transform, augment, or otherwise modify input sequence 5. Output sequence 7 can answer, evaluate, confirm, or otherwise respond to input sequence 5. Output sequence 7 can implement (or describe instructions for implementing) an instruction provided via input sequence 5.

[0150] Output sequence 7 can be generated autoregressively. For instance, for some applications, an output of one or more prediction layer(s) 6 can be passed through one or more output layers (e.g., softmax layer) to obtain a probability distribution over an output vocabulary (e.g.. a textual or symbolic vocabulary) conditioned on a set of input elements in a context window. In this manner, for instance, output sequence 7 can be autoregressively generated by sampling a likely next output element, adding that element to the context window; and re-generating the probability distribution based on the updated context window, and sampling a likely next output element, and so forth.

[0151] Output sequence 7 can also be generated non-autoregressively. For instance, multiple output elements of output sequence 7 can be predicted together without explicit sequential conditioning on each other. See, e.g., Saharia et al., Non-Autoregressive Machine Translation with Latent Alignments. ARXIV:2004.07437V3 (NOV. 16, 2020).

[0152] Output sequence 7 can include one or multiple portions or elements. In an example content generation configuration, output sequence 7 can include multiple elements corresponding to multiple portions of a generated output sequence (e.g., a textual sentence, values of a discretized waveform, computer code, etc.). In an example classification configuration, output sequence 7 can include a single element associated with a classification output. For instance, an output “vocabulary’’ can include a set of classes into which an inputsequence is to be classified. For instance, a vision transformer block can pass latent state information to a multilayer perceptron that outputs a likely class value associated with an input image.

[0153] Figure 11 is a block diagram of an example technique for populating an example input sequence 8. Input sequence 8 can include various functional elements that form part of the model infrastructure, such as an element 8-0 obtained from a task indicator 9 that signals to any model(s) that process input sequence 8 that a particular task is being performed (e.g., to help adapt a performance of the model(s) to that particular task). Input sequence 8 can include various data elements from different data modalities. For instance, an input modality 10-1 can include one modality of data. A data-to-sequence model 11-1 can process data from input modality 10-1 to project the data into a format compatible with input sequence 8 (e.g., one or more vectors dimensioned according to the dimensions of input sequence 8) to obtain elements 8-1, 8-2, 8-3. Another input modality 10-2 can include a different modality7of data. A data-to-sequence model 11-2 can project data from input modality 10-2 into a format compatible with input sequence 8 to obtain elements 8-4, 8-5, 8- 6. Another input modality 10-3 can include yet another different modality of data. A data-to- sequence model 11-3 can project data from input modality 10-3 into a format compatible with input sequence 8 to obtain elements 8-7, 8-8, 8-9.

[0154] Input sequence 8 can be the same as or different from input sequence 5. Input sequence 8 can be a multimodal input sequence that contains elements that represent data from different modalities using a common dimensional representation. For instance, an embedding space can have dimensions. Input sequence 8 can be configured to contain a plurality of elements that have P dimensions. In this manner, for instance, example implementations can facilitate information extraction and reasoning across diverse data modalities by projecting data into elements in the same embedding space for comparison, combination, or other computations therebetween.

[0155] For example, elements 8-0, . . . , 8-9 can indicate particular locations within a multidimensional embedding space. Some elements can map to a set of discrete locations in the embedding space. For instance, elements that correspond to discrete members of a predetermined vocabulary of tokens can map to discrete locations in the embedding space that are associated with those tokens. Other elements can be continuously distributed across the embedding space. For instance, some data types can be broken down into continuously defined portions (e.g., image patches) that can be described using continuously distributed locations within the embedding space.

[0156] In some implementations, the expressive power of the embedding space may not be limited to meanings associated with any particular set of tokens or other building blocks. For example, a continuous embedding space can encode a spectrum of high-order information. An individual piece of information (e.g., a token) can map to a particular point in that space: for instance, a token for the word “dog” can be projected to an embedded value that points to a particular location in the embedding space associated with canine-related information. Similarly, an image patch of an image of a dog on grass can also be projected into the embedding space. In some implementations, the projection of the image of the dog can be similar to the projection of the word “dog” while also having similarity to a projection of the word “grass.” while potentially being different from both. In some implementations, the projection of the image patch may not exactly align with any single projection of a single word. In some implementations, the projection of the image patch can align with a combination of the projections of the words “dog” and “grass.” In this manner, for instance, a high-order embedding space can encode information that can be independent of data modalities in which the information is expressed.

[0157] Task indicator 9 can include a model or model component configured to identify a task being performed and inject, into input sequence 8, an input value represented by element 8-0 that signals which task is being performed. For instance, the input value can be provided as a data type associated with an input modality and projected along with that input modality (e.g., the input value can be a textual task label that is embedded along with other textual data in the input; the input value can be a pixel-based representation of a task that is embedded along with other image data in the input; etc.). The input value can be provided as a data type that differs from or is at least independent from other input(s). For instance, the input value represented by element 8-0 can be a learned within a continuous embedding space.

[0158] Input modalities 10-1, 10-2, and 10-3 can be associated with various different data types (e.g., as described above with respect to input(s) 2 and output(s) 3).

[0159] Data-to-sequence models 11-1. 11-2. and 11-3 can be the same or different from each other. Data-to-sequence models 11 -I, 11-2, and 11-3 can be adapted to each respective input modality 10-1, 10-2, and 10-3. For example, a textual data-to-sequence model can subdivide a portion of input text and project the subdivisions into element(s) in input sequence 8 (e.g., elements 8-1. 8-2, 8-3, etc.). An image data-to-sequence model can subdivide an input image and project the subdivisions into element(s) in input sequence 8 (e.g., elements 8-4, 8-5, 8-6, etc.). An arbitrary datatype data-to-sequence model cansubdivide an input of that arbitrary datatype and project the subdivisions into element(s) in input sequence 8 (e.g., elements 8-7. 8-8, 8-9, etc.).

[0160] Data-to-sequence models 1 1-1, 1 1-2, and 11-3 can form part of machine- learned sequence processing model (s) 4. Data-to-sequence models 11-1, 11-2, and 11-3 can be jointly trained with or trained independently from machine-learned sequence processing model(s) 4. Data-to-sequence models 11-1, 11-2, and 11-3 can be trained end-to-end with machine-learned sequence processing model(s) 4.Example Machine-Learned Model Development Platform

[0161] Figure 12 is a block diagram of an example model development platform 12 that can facilitate creation, adaptation, and refinement of example machine-learned models (e.g., machine-learned model(s) 1, sequence processing model(s) 4, etc ). Model development platform 12 can provide a number of different toolkits that developer systems can employ in the development of new or adapted machine-learned models.

[0162] Model development platform 12 can provide one or more model libraries 13 containing building blocks for new models. Model libraries 13 can include one or more pretrained foundational models 13-1, which can provide a backbone of processing power across various tasks. Model libraries 13 can include one or more pre-trained expert models 13-2, which can be focused on performance in particular domains of expertise. Model libraries 13 can include various model primitives 13-3, which can provide low-level architectures or components (optionally pre-trained), which can be assembled in various arrangements as desired.

[0163] Model development platform 12 can receive selections of various model components 14. Model development platform 12 can pass selected model components 14 to a workbench 15 that combines selected model components 14 into a development model 16.

[0164] Workbench 15 can facilitate further refinement and adaptation of development model 16 by leveraging a number of different toolkits integrated with model development platform 12. For example, workbench 15 can facilitate alignment of the development model 16 with a desired performance profile on various tasks using a model alignment toolkit 17.

[0165] Model alignment toolkit 17 can provide a number of tools for causing development model 16 to generate outputs aligned with desired behavioral characteristics. Alignment can include increasing an accuracy, precision, recall, etc. of model outputs.Alignment can include enforcing output styles, schema, or other preferential characteristics of model outputs. Alignment can be general or domain-specific. For instance, a pre-trainedfoundational model 13-1 can begin with an initial level of performance across multiple domains. Alignment of the pre-trained foundational model 13-1 can include improving a performance in a particular domain of information or tasks (e.g., even at the expense of performance in another domain of information or tasks).

[0166] Model alignment toolkit 17 can integrate one or more dataset(s) 17-1 for aligning development model 16. Curated dataset(s) 17-1 can include labeled or unlabeled training data. Dataset(s) 17-1 can be obtained from public domain datasets. Dataset(s) 17-1 can be obtained from private datasets associated with one or more developer system(s) for the alignment of bespoke machine-learned model(s) customized for private use-cases.

[0167] Pre-training pipelines 17-2 can include a machine-learned model training workflow configured to update development model 16 over large-scale, potentially noisy datasets. For example, pre-training can leverage unsupervised learning techniques (e.g., denoising, etc.) to process large numbers of training instances to update model parameters from an initialized state and achieve a desired baseline performance. Pre- training pipelines 17-2 can leverage unlabeled datasets in dataset(s) 17-1 to perform pre-training. Workbench 15 can implement a pre-training pipeline 17-2 to pre-train development model 16.

[0168] Fine-tuning pipelines 17-3 can include a machine-learned model training workflow configured to refine the model parameters of development model 16 with higher- quality data. Fine-tuning pipelines 17-3 can update development model 16 by conducting supervised training with labeled dataset(s) in dataset(s) 17-1. Fine-tuning pipelines 17-3 can update development model 16 by conducting reinforcement learning using reward signals from user feedback signals. Workbench 15 can implement a fine-tuning pipeline 17-3 to finetune development model 16.

[0169] Prompt libraries 17-4 can include sets of inputs configured to induce behavior aligned with desired performance criteria. Prompt libraries 17-4 can include few-shot prompts (e.g., inputs providing examples of desired model outputs for prepending to a desired runtime query), chain-of-thought prompts (e.g., inputs providing step-by-step reasoning within the exemplars to facilitate thorough reasoning by the model), and the like.

[0170] Example prompts can be retrieved from an available repository of prompt libraries 17-4. Example prompts can be contributed by one or more developer systems using workbench 15.

[0171] In some implementations, pre-trained or fine-tuned models can achieve satisfactory performance without exemplars in the inputs. For instance, zero-shot prompts caninclude inputs that lack exemplars. Zero-shot prompts can be within a domain within a training dataset or outside of the training domain(s).

[0172] Prompt libraries 17-4 can include one or more prompt engineering tools. Prompt engineering tools can provide workflows for retrieving or learning optimized prompt values. Prompt engineering tools can facilitate directly learning prompt values (e.g., input element values) based one or more training iterations. Workbench 15 can implement prompt engineering tools in development model 16.

[0173] Prompt libraries 17-4 can include pipelines for prompt generation. For example, inputs can be generated using development model 16 itself or other machine- learned models. In this manner, for instance, a first model can process information about a task and output a input for a second model to process in order to perform a step of the task. The second model can be the same as or different from the first model. Workbench 15 can implement prompt generation pipelines in development model 16.

[0174] Prompt libraries 17-4 can include pipelines for context injection. For instance, a performance of development model 16 on a particular task can improve if provided with additional context for performing the task. Prompt libraries 17-4 can include software components configured to identify desired context, retrieve the context from an external source (e.g., a database, a sensor, etc.), and add the context to the input prompt. Workbench 15 can implement context injection pipelines in development model 16.

[0175] Although various training examples described herein with respect to model development platform 12 refer to ‘'pre-training” and “fine-tuning,” it is to be understood that model alignment toolkit 17 can generally support a wide variety of training techniques adapted for training a wide variety of machine-learned models. Example training techniques can correspond to the example training method 800 described above.

[0176] Model development platform 12 can include a model plugin toolkit 18. Model plugin toolkit 18 can include a variety of tools configured for augmenting the functionality' of a machine-learned model by integrating the machine-learned model w ith other systems, devices, and software components. For instance, a machine-learned model can use tools to increase performance quality where appropriate. For instance, deterministic tasks can be offloaded to dedicated tools in lieu of probabilistically performing the task with an increased risk of error. For instance, instead of autoregressively predicting the solution to a system of equations, a machine-learned model can recognize a tool to call for obtaining the solution and pass the system of equations to the appropriate tool. The tool can be a traditional system of equations solver that can operate deterministically to resolve the system of equations. Theoutput of the tool can be returned in response to the original query. In this manner, tool use can allow some example models to focus on the strengths of machine-learned models — e.g., understanding an intent in an unstructured request for a task — while augmenting the performance of the model by offloading certain tasks to a more focused tool for rote application of deterministic algorithms to a well-defined problem.

[0177] Model plugin toolkit 18 can include validation tools 18-1. Validation tools 18- 1 can include tools that can parse and confirm output(s) of a machine-learned model.Validation tools 18-1 can include engineered heuristics that establish certain thresholds applied to model outputs. For example, validation tools 18-1 can ground the outputs of machine-learned models to structured data sources (e.g., to mitigate ‘‘hallucinations’').

[0178] Model plugin toolkit 18 can include tooling packages 18-2 for implementing one or more tools that can include scripts or other executable code that can be executed alongside development model 16. Tooling packages 18-2 can include one or more inputs configured to cause machine-learned model(s) to implement the tools (e.g., few-shot prompts that induce a model to output tool calls in the proper syntax, etc.). Tooling packages 18-2 can include, for instance, fine-tuning training data for training a model to use a tool.

[0179] Model plugin toolkit 18 can include interfaces for calling external application programming interfaces (APIs) 18-3. For instance, in addition to or in lieu of implementing tool calls or tool code directly with development model 16, development model 16 can be aligned to output instruction that initiate API calls to send or obtain data via external systems.

[0180] Model plugin toolkit 18 can integrate with prompt libraries 17-4 to build a catalog of available tools for use with development model 16. For instance, a model can receive, in an input, a catalog of available tools, and the model can generate an output that selects a tool from the available tools and initiates a tool call for using the tool.

[0181] Model development platform 12 can include a computational optimization toolkit 19 for optimizing a computational performance of development model 16. For instance, tools for model compression 19-1 can allow development model 16 to be reduced in size while maintaining a desired level of performance. For instance, model compression 19-1 can include quantization workflows, weight pruning and sparsification techniques, etc. Tools for hardware acceleration 19-2 can facilitate the configuration of the model storage and execution formats to operate optimally on different hardware resources. For instance, hardware acceleration 19-2 can include tools for optimally sharding models for distributed processing over multiple processing units for increased bandwidth, lower unified memory requirements, etc. Tools for distillation 19-3 can provide for the training of lighter-weightmodels based on the knowledge encoded in development model 16. For instance, development model 16 can be a highly performant, large machine-learned model optimized using model development platform 12. To obtain a lightweight model for running in resource-constrained environments, a smaller model can be a “student model” that learns to imitate development model 16 as a “teacher model.” In this manner, for instance, the investment in learning the parameters and configurations of development model 16 can be efficiently transferred to a smaller model for more efficient inference.

[0182] Workbench 15 can implement one, multiple, or none of the toolkits implemented in model development platform 12. Workbench 15 can output an output model 20 based on development model 16. Output model 20 can be a deployment version of development model 16. Output model 20 can be a development or training checkpoint of development model 16. Output model 20 can be a distilled, compressed, or otherwise optimized version of development model 16.

[0183] Figure 13 is a block diagram of an example training flow for training a machine-learned development model 16. One or more portion(s) of the example training flow can be implemented by a computing system that includes one or more computing devices such as, for example, computing systems described with reference to the other figures. Each respective portion of the example training flow can be performed by any (or any combination) of one or more computing devices. Moreover, one or more portion(s) of the example training flow can be implemented on the hardware components of the device(s) described herein, for example, to train one or more systems or models. FIG. 13 depicts elements performed in a particular order for purposes of illustration and discussion. Those of ordinary skill in the art, using the disclosures provided herein, will understand that the elements of any of the methods discussed herein can be adapted, rearranged, expanded, omitted, combined, or modified in various ways without deviating from the scope of the present disclosure. FIG. 13 is described with reference to elements / terms described with respect to other systems and figures for exemplar}' illustrated purposes and is not meant to be limiting. One or more portions of the example training flow can be performed additionally, or alternatively, by other systems.

[0184] Initially, development model 16 can persist in an initial state as an initialized model 21. Development model 16 can be initialized with weight values. Initial weight values can be random or based on an initialization schema. Initial weight values can be based on prior pre-training for the same or for a different model.

[0185] Initialized model 21 can undergo pre-training in a pre-training stage 22. Pretraining stage 22 can be implemented using one or more pre-training pipelines 17-2 over data from dataset(s) 17-1. Pre-training can be omitted, for example, if initialized model 21 is already pre-trained (e.g., development model 16 contains, is, or is based on a pre-trained foundational model or an expert model).

[0186] Pre-trained model 23 can then be a new version of development model 16, which can persist as development model 16 or as a new development model. Pre-trained model 23 can be the initial state if development model 16 was already pre-trained. Pre-trained model 23 can undergo fine-tuning in a fine-tuning stage 24. Fine-tuning stage 24 can be implemented using one or more fine-tuning pipelines 17-3 over data from dataset(s) 17-1. Fine-tuning can be omitted, for example, if a pre-trained model as satisfactory performance, if the model was already fine-tuned, or if other tuning approaches are preferred.

[0187] Fine-tuned model 25 can then be a new version of development model 16, which can persist as development model 16 or as a new development model. Fine-tuned model 25 can be the initial state if development model 16 was already fine-tuned. Fine-tuned model 25 can undergo refinement with user feedback 26. For instance, refinement with user feedback 26 can include reinforcement learning, optionally based on human feedback from human users of fine-tuned model 25. As reinforcement learning can be a form of fine-tuning, it is to be understood that fine-tuning stage 24 can subsume the stage for refining with user feedback 26. Refinement with user feedback 26 can produce a refined model 27. Refined model 27 can be output to downstream system(s) 28 for deployment or further development.

[0188] In some implementations, computational optimization operations can be applied before, during, or after each stage. For instance, initialized model 21 can undergo computational optimization 29-1 (e.g.. using computational optimization toolkit 19) before pre-training stage 22. Pre-trained model 23 can undergo computational optimization 29-2 (e.g., using computational optimization toolkit 19) before fine-tuning stage 24. Fine-tuned model 25 can undergo computational optimization 29-3 (e.g., using computational optimization toolkit 19) before refinement with user feedback 26. Refined model 27 can undergo computational optimization 29-4 (e.g., using computational optimization toolkit 19) before output to downstream system(s) 28. Computational optimization(s) 29-1, . . . , 29-4 can all be the same, all be different, or include at least some different optimization techniques.Example Machine-Learned Model Inference System

[0189] Figure 14 is a block diagram of an inference system for operating one or more machine-learned model(s) 1 to perform inference (e.g., for training, for deployment, etc.). A model host 31 can receive machine-learned model(s) 1. Model host 31 can host one or more model instance(s) 31-1, which can be one or multiple instances of one or multiple models. Model host 31 can host model instance(s) 31-1 using available compute resources 31-2 associated with model host 31.

[0190] Model host 31 can perform inference on behalf of one or more client(s) 32. Client(s) 32 can transmit an input request 33 to model host 31. Using input request 33, model host 31 can obtain input(s) 2 for input to machine-learned model(s) 1. Machine-learned model(s) 1 can process input(s) 2 to generate output(s) 3. Using output(s) 3, model host 31 can return an output payload 34 for responding to input request 33 from client(s) 32. Output payload 34 can include or be based on output(s) 3.

[0191] Model host 31 can leverage various other resources and tools to augment the inference task. For instance, model host 31 can communicate with tool interfaces 35 to facilitate tool use by model instance(s) 31-1. Tool interfaces 35 can include local or remote APIs. Tool interfaces 35 can include integrated scripts or other software functionality. Model host 31 can engage online learning interface(s) 36 to facilitate ongoing improvements to machine-learned model(s) 1. For instance, online learning interface(s) 36 can be used within reinforcement learning loops to retrieve user feedback on inferences served by model host 31. Model host 31 can access runtime data source(s) 37 for augmenting input(s) 2 with additional contextual information. For instance, runtime data source(s) 37 can include a knowledge graph 37-1 that facilitates structured information retrieval for information associated with input request(s) 33 (e.g., a search engine service). Runtime data source(s) 37 can include public or private, external or local database(s) 37-2 that can store information associated with input request(s) 33 for augmenting input(s) 2. Runtime data source(s) 37 can include account data 37-3 which can be retrieved in association with a user account corresponding to a client 32 for customizing the behavior of model host 31 accordingly.

[0192] Model host 31 can be implemented by one or multiple computing devices or systems. Client(s) 2 can be implemented by one or multiple computing devices or systems, which can include computing devices or systems shared with model host 31.

[0193] For example, model host 31 can operate on a server system that provides a machine-learning service to client device(s) that operate client(s) 32 (e.g., over a local or wide-area network). Client device(s) can be end-user devices used by individuals. Clientdevice(s) can be server systems that operate client(s) 32 to provide various functionality as a service to downstream end-user devices.

[0194] In some implementations, model host 31 can operate on a same device or system as client(s) 32. Model host 31 can be a machine-learning service that runs on-device to provide machine-learning functionality to one or multiple applications operating on a client device, which can include an application implementing client(s) 32. Model host 31 can be a part of a same application as client(s) 32. For instance, model host 31 can be a subroutine or method implemented by one part of an application, and client(s) 32 can be another subroutine or method that engages model host 31 to perform inference functions within the application. It is to be understood that model host 31 and client(s) 32 can have various different configurations.

[0195] Model instance(s) 31-1 can include one or more machine-learned models that are available for performing inference. Model instance(s) 31-1 can include weights or other model components that are stored on in persistent storage, temporarily cached, or loaded into high-speed memory. Model instance(s) 31-1 can include multiple instance(s) of the same model (e.g., for parallel execution of more requests on the same model). Model instance(s) 31-1 can include instance(s) of different model(s). Model instance(s) 31-1 can include cached intermediate states of active or inactive model(s) used to accelerate inference of those models. For instance, an inference session with a particular model may generate significant amounts of computational results that can be re-used for future inference runs (e.g., using a KV cache for transformer-based models). These computational results can be saved in association with that inference session so that session can be executed more efficiently when resumed.

[0196] Compute resource(s) 31-2 can include one or more processors (central processing units, graphical processing units, tensor processing units, machine-learning accelerators, etc.) connected to one or more memory devices. Compute resource(s) 31-2 can include a dynamic pool of available resources shared with other processes. Compute resource(s) 31-2 can include memory devices large enough to fit an entire model instance in a single memory instance. Compute resource(s) 31-2 can also shard model instance(s) across multiple memon devices (e.g., using data parallelization or tensor parallelization, etc ). This can be done to increase parallelization or to execute a large model using multiple memoiy devices which individually might not be able to fit the entire model into memory.

[0197] Input request 33 can include data for input(s) 2. Model host 31 can process input request 33 to obtain input(s) 2. Input(s) 2 can be obtained directly from input request 33or can be retrieved using input request 33. Input request 33 can be submitted to model host 31 via an API.

[0198] Model host 31 can perform inference over batches of input requests 33 in parallel. For instance, a model instance 31-1 can be configured with an input structure that has a batch dimension. Separate input(s) 2 can be distributed across the batch dimension (e.g., rows of an array). The separate input(s) 2 can include completely different contexts. The separate input(s) 2 can be multiple inference steps of the same task. The separate input(s) 2 can be staggered in an input structure, such that any given inference cycle can be operating on different portions of the respective input(s) 2. In this manner, for instance, model host 31 can perform inference on the batch in parallel, such that output(s) 3 can also contain the batch dimension and return the inference results for the batched input(s) 2 in parallel. In this manner, for instance, batches of input request(s) 33 can be processed in parallel for higher throughput of output payload(s) 34.

[0199] Output payload 34 can include or be based on output(s) 3 from machine- learned model(s) 1. Model host 31 can process output(s) 3 to obtain output payload 34. This can include chaining multiple rounds of inference (e.g.. iteratively, recursively, across the same model(s) or different model(s)) to arrive at a final output for a task to be returned in output payload 34. Output pay load 34 can be transmitted to client(s) 32 via an API.

[0200] Online learning interface(s) 36 can facilitate reinforcement learning of machine-learned model(s) 1. Online learning interface(s) 36 can facilitate reinforcement learning with human feedback (RLHF). Online learning interface(s) 36 can facilitate federated learning of machine-learned model(s) 1.

[0201] Model host 31 can execute machine-learned model(s) 1 to perform inference for various tasks using various t pes of data. For example, various different input(s) 2 and output(s) 3 can be used for various different tasks. In some implementations, input(s) 2 can be or otherwise represent image data. Machine-learned model(s) 1 can process the image data to generate an output. As an example, machine-learned model(s) 1 can process the image data to generate an image recognition output (e.g., a recognition of the image data, a latent embedding of the image data, an encoded representation of the image data, a hash of the image data, etc.). As another example, machine-learned model(s) 1 can process the image data to generate an image segmentation output. As another example, machine-learned model(s) 1 can process the image data to generate an image classification output. As another example, machine-learned model(s) 1 can process the image data to generate an image data modification output (e.g., an alteration of the image data, etc.). As another example, machine-learned model(s) 1 can process the image data to generate an encoded image data output (e.g., an encoded and / or compressed representation of the image data, etc.). As another example, machine-learned model(s) 1 can process the image data to generate an upscaled image data output. As another example, machine-learned model(s) 1 can process the image data to generate a prediction output.

[0202] In some implementations, the task is a computer vision task. In some cases, input(s) 2 includes pixel data for one or more images and the task is an image processing task. For example, the image processing task can be image classification, where the output is a set of scores, each score corresponding to a different object class and representing the likelihood that the one or more images depict an object belonging to the object class. The image processing task may be object detection, where the image processing output identifies one or more regions in the one or more images and, for each region, a likelihood that region depicts an object of interest. As another example, the image processing task can be image segmentation, where the image processing output defines, for each pixel in the one or more images, a respective likelihood for each category in a predetermined set of categories. For example, the set of categories can be foreground and background. As another example, the set of categories can be object classes. As another example, the image processing task can be depth estimation, where the image processing output defines, for each pixel in the one or more images, a respective depth value. As another example, the image processing task can be motion estimation, where the network input includes multiple images, and the image processing output defines, for each pixel of one of the input images, a motion of the scene depicted at the pixel between the images in the network input.

[0203] In some implementations, input(s) 2 can be or otherwise represent natural language data. Machine-learned model(s) 1 can process the natural language data to generate an output. As an example, machine-learned model(s) 1 can process the natural language data to generate a language encoding output. As another example, machine-learned model(s) 1 can process the natural language data to generate a latent text embedding output. As another example, machine-learned model(s) 1 can process the natural language data to generate a translation output. As another example, machine-learned model(s) 1 can process the natural language data to generate a classification output. As another example, machine-learned model(s) 1 can process the natural language data to generate a textual segmentation output. As another example, machine-learned model(s) 1 can process the natural language data to generate a semantic intent output. As another example, machine-learned model(s) 1 can process the natural language data to generate an upscaled text or natural language output(e.g., text or natural language data that is higher quality than the input text or natural language, etc.). As another example, machine-learned model(s) 1 can process the natural language data to generate a prediction output (e.g., one or more predicted next portions of natural language content).

[0204] In some implementations, input(s) 2 can be or otherwise represent speech data (e.g., data describing spoken natural language, such as audio data, textual data, etc.). Machine-learned model(s) 1 can process the speech data to generate an output. As an example, machine-learned model(s) 1 can process the speech data to generate a speech recognition output. As another example, machine-learned model(s) 1 can process the speech data to generate a speech translation output. As another example, machine-learned model(s) 1 can process the speech data to generate a latent embedding output. As another example, machine-learned model(s) 1 can process the speech data to generate an encoded speech output (e.g., an encoded and / or compressed representation of the speech data, etc.). As another example, machine-learned model(s) 1 can process the speech data to generate an upscaled speech output (e.g., speech data that is higher quality than the input speech data, etc.). As another example, machine-learned model(s) 1 can process the speech data to generate a textual representation output (e g., a textual representation of the input speech data, etc.). As another example, machine-learned model(s) 1 can process the speech data to generate a prediction output.

[0205] In some implementations, input(s) 2 can be or otherwise represent latent encoding data (e.g., a latent space representation of an input, etc ). Machine-learned model(s) 1 can process the latent encoding data to generate an output. As an example, machine- learned model(s) 1 can process the latent encoding data to generate a recognition output. As another example, machine-learned model(s) 1 can process the latent encoding data to generate a reconstruction output. As another example, machine-learned model(s) 1 can process the latent encoding data to generate a search output. As another example, machine- learned model(s) 1 can process the latent encoding data to generate a reclustering output. As another example, machine-learned model(s) 1 can process the latent encoding data to generate a prediction output.

[0206] In some implementations, input(s) 2 can be or otherwise represent statistical data. Statistical data can be, represent, or otherwise include data computed and / or calculated from some other data source. Machine-learned model(s) 1 can process the statistical data to generate an output. As an example, machine-learned model(s) 1 can process the statistical data to generate a recognition output. As another example, machine-learned model(s) 1 canprocess the statistical data to generate a prediction output. As another example, machine- learned model(s) 1 can process the statistical data to generate a classification output. As another example, machine-learned model(s) 1 can process the statistical data to generate a segmentation output. As another example, machine-learned model(s) 1 can process the statistical data to generate a visualization output. As another example, machine-learned model(s) 1 can process the statistical data to generate a diagnostic output.

[0207] In some implementations, input(s) 2 can be or otherwise represent sensor data. Machine-learned model(s) 1 can process the sensor data to generate an output. As an example, machine-learned model(s) 1 can process the sensor data to generate a recognition output. As another example, machine-learned model(s) 1 can process the sensor data to generate a prediction output. As another example, machine-learned model(s) 1 can process the sensor data to generate a classification output. As another example, machine-learned model(s) 1 can process the sensor data to generate a segmentation output. As another example, machine-learned model(s) 1 can process the sensor data to generate a visualization output. As another example, machine-learned model(s) 1 can process the sensor data to generate a diagnostic output. As another example, machine-learned model(s) 1 can process the sensor data to generate a detection output.

[0208] In some implementations, machine-learned model(s) 1 can be configured to perform a task that includes encoding input data for reliable and / or efficient transmission or storage (and / or corresponding decoding). For example, the task may be an audio compression task. The input may include audio data and the output may comprise compressed audio data. In another example, the input includes visual data (e.g. one or more images or videos), the output comprises compressed visual data, and the task is a visual data compression task. In another example, the task may comprise generating an embedding for input data (e.g. input audio or visual data). In some cases, the input includes audio data representing a spoken utterance and the task is a speech recognition task. The output may comprise a text output which is mapped to the spoken utterance. In some cases, the task comprises encry pting or decrypting input data. In some cases, the task comprises a microprocessor performance task, such as branch prediction or memory address translation.

[0209] In some implementations, the task is a generative task, and machine-learned model(s) 1 can be configured to output content generated in view of input(s) 2. For instance, input(s) 2 can be or otherwise represent data of one or more modalities that encodes context for generating additional content.

[0210] In some implementations, the task can be a text completion task. Machine- learned model(s) 1 can be configured to process input(s) 2 that represent textual data and to generate output(s) 3 that represent additional textual data that completes a textual sequence that includes input(s) 2. For instance, machine-learned model(s) 1 can be configured to generate output(s) 3 to complete a sentence, paragraph, or portion of text that follows from a portion of text represented by input(s) 2.

[0211] In some implementations, the task can be an instruction following task. Machine-learned model(s) 1 can be configured to process input(s) 2 that represent instructions to perform a function and to generate output(s) 3 that advance a goal of satisfying the instruction function (e.g., at least a step of a multi-step procedure to perform the function). Output(s) 3 can represent data of the same or of a different modality as input(s) 2. For instance, input(s) 2 can represent textual data (e.g., natural language instructions for a task to be performed) and machine-learned model(s) 1 can process input(s) 2 to generate output(s) 3 that represent textual data responsive to the instructions (e.g., natural language responses, programming language responses, machine language responses, etc.). Input(s) 2 can represent image data (e.g.. image-based instructions for a task to be performed, optionally accompanied by textual instructions) and machine-learned model(s) 1 can process input(s) 2 to generate output(s) 3 that represent textual data responsive to the instructions (e.g., natural language responses, programming language responses, machine language responses, etc.). One or more output(s) 3 can be iteratively or recursively generated to sequentially process and accomplish steps toward accomplishing the requested functionality. For instance, an initial output can be executed by an external system or be processed by machine-learned model(s) 1 to complete an initial step of performing a function. Multiple steps can be performed, with a final output being obtained that is responsive to the initial instructions.

[0212] In some implementations, the task can be a question answering task. Machine- learned model(s) 1 can be configured to process input(s) 2 that represent a question to answer and to generate output(s) 3 that advance a goal of returning an answer to the question (e.g., at least a step of a multi-step procedure to perform the function). Output(s) 3 can represent data of the same or of a different modality as input(s) 2. For instance, input(s) 2 can represent textual data (e.g., natural language instructions for a task to be performed) and machine- learned model(s) 1 can process input(s) 2 to generate output(s) 3 that represent textual data responsive to the question (e.g., natural language responses, programming language responses, machine language responses, etc.). Input(s) 2 can represent image data (e.g., image-based instructions for a task to be performed, optionally accompanied by textualinstructions) and machine-learned model(s) 1 can process input(s) 2 to generate output(s) 3 that represent textual data responsive to the question (e.g., natural language responses, programming language responses, machine language responses, etc.). One or more output(s) 3 can be iteratively or recursively generated to sequentially process and accomplish steps toward answering the question. For instance, an initial output can be executed by an external system or be processed by machine-learned model(s) 1 to complete an initial step of obtaining an answer to the question (e.g., querying a database, performing a computation, executing a script, etc.). Multiple steps can be performed, with a final output being obtained that is responsive to the question.

[0213] In some implementations, the task can be an image generation task. Machine- learned model(s) 1 can be configured to process input(s) 2 that represent context regarding a desired portion of image content. The context can include text data, image data, audio data, etc. Machine-learned model(s) 1 can be configured to generate output(s) 3 that represent image data that depicts imagery7related to the context. For instance, machine-learned model(s) 1 can be configured to generate pixel data of an image. Values for channel (s) associated with the pixels in the pixel data can be selected based on the context (e.g.. based on a probability determined based on the context).

[0214] In some implementations, the task can be an audio generation task. Machine- learned model(s) 1 can be configured to process input(s) 2 that represent context regarding a desired portion of audio content. The context can include text data, image data, audio data, etc. Machine-learned model(s) 1 can be configured to generate output(s) 3 that represent audio data related to the context. For instance, machine-learned model (s) 1 can be configured to generate waveform data in the form of an image (e.g., a spectrogram). Values for channel(s) associated with pixels of the image can be selected based on the context. Machine- learned model(s) 1 can be configured to generate waveform data in the form of a sequence of discrete samples of a continuous waveform. Values of the sequence can be selected based on the context (e.g., based on a probability7determined based on the context).

[0215] In some implementations, the task can be a data generation task. Machine- learned model(s) 1 can be configured to process input(s) 2 that represent context regarding a desired portion of data (e.g., data from various data domains, such as sensor data, image data, multimodal data, statistical data, etc.). The desired data can be, for instance, synthetic data for training other machine-learned models. The context can include arbitrary data type(s). Machine-learned model(s) 1 can be configured to generate output(s) 3 that represent data that aligns with the desired data. For instance, machine-learned model (s) 1 can be configured togenerate data values for populating a dataset. Values for the data object(s) can be selected based on the context (e.g., based on a probability determined based on the context).Example Computing Systems and Devices

[0216] Figure 15 is a block diagram of an example networked computing system that can perform aspects of example implementations of the present disclosure. The system can include a number of computing devices and systems that are communicatively coupled over a network 49. An example computing device 50 is described to provide an example of a computing device that can perform any aspect of the present disclosure (e.g., implementing model host 31, client(s) 32, or both). An example server computing system 60 is described as an example of a server computing system that can perform any aspect of the present disclosure (e.g., implementing model host 31, client(s) 32, or both). Computing device 50 and server computing system(s) 60 can cooperatively interact (e.g., over network 49) to perform any aspect of the present disclosure (e.g., implementing model host 31, client(s) 32, or both). Model development platform system 70 is an example system that can host or serve model development platform(s) 12 for development of machine-learned models. Third-party system(s) 80 are example system(s) with which any of computing device 50, server computing system(s) 60, or model development platform system(s) 70 can interact in the performance of various aspects of the present disclosure (e.g., engaging third-party tools, accessing third-party databases or other resources, etc.).

[0217] Network 49 can be any type of communications network, such as a local area network (e.g., intranet), wide area network (e.g., Internet), or some combination thereof and can include any number of wired or wireless links. In general, communication over network 49 can be carried via any type of wired or wireless connection, using a wide variety of communication protocols (e.g., TCP / IP, HTTP, SMTP, FTP), encodings or formats (e.g., HTML, XML), or protection schemes (e.g., VPN, secure HTTP, SSL). Network 49 can also be implemented via a system bus. For instance, one or more devices or systems of Figure 15 can be co-located with, contained by, or otherwise integrated into one or more other devices or systems.

[0218] Computing device 50 can be any type of computing device, such as, for example, a personal computing device (e.g., laptop or desktop), a mobile computing device (e.g., smartphone or tablet), a gaming console or controller, a wearable computing device, an embedded computing device, a server computing device, a virtual machine operating on a host device, or any other type of computing device. Computing device 50 can be a clientcomputing device. Computing device 50 can be an end-user computing device. Computing device 50 can be a computing device of a service provided that provides a service to an end user (who may use another computing device to interact with computing device 50).

[0219] Computing device 50 can include one or more processors 51 and a memory 52. Processor(s) 51 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, an FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Memory 52 can include one or more non-transitory computer-readable storage media, such as HBM, RAM, ROM, EEPROM, EPROM, flash memory' devices, magnetic disks, etc., and combinations thereof. Memory 52 can store data 53 and instructions 54 which can be executed by processor(s) 51 to cause computing device 50 to perform operations. The operations can implement any one or multiple features described herein. The operations can implement example methods and techniques described herein.

[0220] Computing device 50 can also include one or more input components that receive user input. For example, a user input component can be a touch-sensitive component (e.g.. a touch-sensitive display screen or a touch pad) that is sensitive to the touch of a user input object (e.g., a finger or a stylus). The touch-sensitive component can serve to implement a virtual keyboard. Other example user input components include a microphone, camera, LIDAR, a physical keyboard or other buttons, or other means by which a user can provide user input.

[0221] Computing device 50 can store or include one or more machine-learned models 55. Machine-learned models 55 can include one or more machine-learned model(s) 1, such as a sequence processing model 4. Machine-learned models 55 can include one or multiple model instance(s) 31-1. Machine-learned model(s) 55 can be received from server computing system(s) 60, model development platform system 70, third party system(s) 80 (e.g., an application distribution platform), or developed locally on computing device 50. Machine-learned model(s) 55 can be loaded into memory 52 and used or otherwise implemented by processor(s) 51. Computing device 50 can implement multiple parallel instances of machine-learned model(s) 55.

[0222] Server computing system(s) 60 can include one or more processors 61 and a memory 62. Processor(s) 61 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, an FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Memory’ 62 can include one or more non-transitory computer-readable storage media, such as HBM, RAM, ROM,EEPROM, EPROM, flash memory' devices, magnetic disks, etc., and combinations thereof. Memory 62 can store data 63 and instructions 64 which can be executed by processor(s) 61 to cause server computing system(s) 60 to perform operations. The operations can implement any one or multiple features described herein. The operations can implement example methods and techniques described herein.

[0223] In some implementations, server computing system 60 includes or is otherwise implemented by one or multiple server computing devices. In instances in which server computing system 60 includes multiple server computing devices, such server computing devices can operate according to sequential computing architectures, parallel computing architectures, or some combination thereof.

[0224] Server computing system 60 can store or otherwise include one or more machine-learned models 65. Machine-learned model(s) 65 can be the same as or different from machine-learned model(s) 55. Machine-learned models 65 can include one or more machine-learned model(s) 1, such as a sequence processing model 4. Machine-learned models 65 can include one or multiple model instance(s) 31-1. Machine-learned model(s) 65 can be received from computing device 50, model development platform system 70. third party system(s) 80, or developed locally on server computing system(s) 60. Machine-learned model(s) 65 can be loaded into memory' 62 and used or otherwise implemented by processor(s) 61. Server computing system(s) 60 can implement multiple parallel instances of machine-learned model(s) 65.

[0225] In an example configuration, machine-learned models 65 can be included in or otherwise stored and implemented by server computing system 60 to establish a client-server relationship with computing device 50 for serving model inferences. For instance, server computing system(s) 60 can implement model host 31 on behalf of client(s) 32 on computing device 50. For instance, machine-learned models 65 can be implemented by server computing system 60 as a portion of a web service (e.g., remote machine-learned model hosting service, such as an online interface for performing machine-learned model operations over a network on server computing system(s) 60). For instance, server computing system(s) 60 can communicate with computing device 50 over a local intranet or internet connection. For instance, computing device 50 can be a workstation or endpoint in communication with server computing system(s) 60, with implementation of machine-learned models 65 being managed by server computing system(s) 60 to remotely perform inference (e g., for runtime or training operations), with output(s) returned (e.g., cast, streamed, etc.) to computing device50. Machine-learned models 65 can work cooperatively or interoperatively with machine- learned models 55 on computing device 50 to perform various tasks.

[0226] Model development platform system(s) 70 can include one or more processors 71 and a memory 72. Processor(s) 71 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, an FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Memory 72 can include one or more non-transitory computer-readable storage media, such as HBM, RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof. Memory 72 can store data 73 and instructions 74 which can be executed by processor(s) 71 to cause model development platform system(s) 70 to perform operations. The operations can implement any one or multiple features described herein. The operations can implement example methods and techniques described herein. Example operations include the functionality described herein with respect to model development platform 12. This and other functionality7can be implemented by developer tool(s) 75.

[0227] Third-party system(s) 80 can include one or more processors 81 and a memory 82. Processor(s) 81 can be any suitable processing device (e.g.. a processor core, a microprocessor, an ASIC, an FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Memory782 can include one or more non-transitory computer-readable storage media, such as HBM, RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof. Memory 82 can store data 83 and instructions 84 which can be executed by processor(s) 81 to cause third-party system(s) 80 to perform operations. The operations can implement any one or multiple features described herein. The operations can implement example methods and techniques described herein. Example operations include the functionality described herein with respect to tools and other external resources called when training or performing inference with machine-learned model(s) 1, 4, 16, 20, 55, 65, etc. (e.g., third-party resource(s) 85).

[0228] Figure 15illustrates one example arrangement of computing systems that can be used to implement the present disclosure. Other computing system configurations can be used as well. For example, in some implementations, one or both of computing system 50 or server computing system(s) 60 can implement all or a portion of the operations of model development platform system 70. For example, computing system 50 or server computing system(s) 60 can implement developer tool(s) 75 (or extensions thereof) to develop, update / train, or refine machine-learned models 1, 4, 16, 20, 55, 65, etc. using one or moretechniques described herein with respect to model alignment toolkit 17. In this manner, for instance, computing system 50 or server computing system(s) 60 can develop, update / train, or refine machine-learned models based on local datasets (e.g., for model personalization / customization, as permitted by user data preference selections).

[0229] Figure 16 is a block diagram of an example computing device 98 that performs according to example embodiments of the present disclosure. Computing device 98 can be a user computing device or a server computing device (e.g., computing device 50, server computing system(s) 60, etc ). Computing device 98 can implement model host 31. For instance, computing device 98 can include a number of applications (e.g., applications 1 through N). Each application can contain its own machine learning library and machine- learned model(s). For example, each application can include a machine-learned model. Example applications include a text messaging application, an email application, a dictation application, a virtual keyboard application, a browser application, etc. As illustrated in Figure 1 , each application can communicate with a number of other components of the computing device, such as, for example, one or more sensors, a context manager, a device state component, or additional components. In some implementations, each application can communicate with each device component using an API (e.g., a public API). In some implementations, the API used by each application is specific to that application.

[0230] Figure 17 is a block diagram of an example computing device 99 that performs according to example embodiments of the present disclosure. Computing device 99 can be the same as or different from computing device 98. Computing device 99 can be a user computing device or a server computing device (e.g., computing device 50, server computing system(s) 60. etc.). Computing device 98 can implement model host 31. For instance, computing device 99 can include a number of applications (e.g., applications 1 through N). Each application can be in communication with a central intelligence layer. Example applications include a text messaging application, an email application, a dictation application, a virtual keyboard application, a browser application, etc. In some implementations, each application can communicate with the central intelligence layer (and model(s) stored therein) using an API (e.g., a common API across all applications).

[0231] The central intelligence layer can include a number of machine-learned models. For example, as illustrated in Figure 17, a respective machine-learned model can be provided for each application and managed by the central intelligence layer. In other implementations, two or more applications can share a single machine-learned model. For example, in some implementations, the central intelligence layer can provide a single modelfor all of the applications. In some implementations, the central intelligence layer is included within or otherwise implemented by an operating system of computing device 99.

[0232] The central intelligence layer can communicate with a central device data layer. The central device data layer can be a centralized repository of data for computing device 99. As illustrated in Figure 17, the central device data layer can communicate with a number of other components of the computing device, such as, for example, one or more sensors, a context manager, a device state component, or additional components. In some implementations, the central device data layer can communicate with each device component using an API (e.g., a private API).Additional Disclosure

[0233] The technology discussed herein makes reference to servers, databases, software applications, and other computer-based systems, as well as actions taken and information sent to and from such systems. The inherent flexibility of computer-based systems allows for a great variety of possible configurations, combinations, and divisions of tasks and functionality between and among components. For instance, processes discussed herein can be implemented using a single device or component or multiple devices or components working in combination. Databases and applications can be implemented on a single system or distributed across multiple systems. Distributed components can operate sequentially or in parallel.

[0234] While the present subject matter has been described in detail with respect to various specific example embodiments thereof, each example is provided by way of explanation, not limitation of the disclosure. Those skilled in the art, upon attaining an understanding of the foregoing, can readily produce alterations to, variations of, and equivalents to such embodiments. Accordingly, the subject disclosure does not preclude inclusion of such modifications, variations or additions to the present subject matter as would be readily apparent to one of ordinary skill in the art. For instance, features illustrated or described as part of one embodiment can be used with another embodiment to yield a still further embodiment. Thus, it is intended that the present disclosure cover such alterations, variations, and equivalents.

[0235] Aspects of the disclosure have been described in terms of illustrative embodiments thereof. Any and all features in the following claims can be combined or rearranged in any way possible, including combinations of claims not explicitly enumerated in combination together, as the example claim dependencies listed herein should not be readas limiting the scope of possible combinations of features disclosed herein. Accordingly, the scope of the present disclosure is by way of example rather than by way of limitation, and the subject disclosure does not preclude inclusion of such modifications, variations or additions to the present subject matter as would be readily apparent to one of ordinary skill in the art. Moreover, terms are described herein using lists of example elements joined by conjunctions such as “and.” “or,” “but,” etc. It should be understood that such conjunctions are provided for explanatory purposes only. Clauses and other sequences of items joined by a particular conjunction such as “or,” for example, can refer to “and / or,” “at least one of’, “any combination of’ example elements listed therein, etc. Terms such as “based on” should be understood as “based at least in part on.”

[0236] The term “can” should be understood as referring to a possibility of a feature in various implementations and not as prescribing an ability7that is necessarily present in every7implementation. For example, the phrase “X can perform Y” should be understood as indicating that, in various implementations, X has the potential to be configured to perform Y, and not as indicating that in every’ instance X must always be able to perform Y. It should be understood that, in various implementations. X might be unable to perform Y and remain within the scope of the present disclosure.

[0237] The term “may” should be understood as referring to a possibility' of a feature in various implementations and not as prescribing an ability that is necessarily present in every implementation. For example, the phrase “X may perform Y” should be understood as indicating that, in various implementations, X has the potential to be configured to perform Y, and not as indicating that in every' instance X must always be able to perform Y. It should be understood that, in various implementations, X might be unable to perform Y and remain within the scope of the present disclosure.

Claims

WHAT IS CLAIMED IS:

1. A computer-implemented method for authorization-aware training of a plurality of machine-learned models, comprising: obtaining, by one or more computing devices, a training dataset comprising a plurality of data items; obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item; determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset, wherein the access authorization data indicates that a first entity is authorized to access each data item of the first subset, and wherein the access authorization data indicates that a second entity is authorized to access each data item of the first subset; determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset, wherein the access authorization data indicates that the first entity is authorized to access each data item of the second subset, and wherein the access authorization data does not indicate that the second entity is authorized to access at least one data item of the second subset; training, by the one or more computing devices based on the first subset, a first machine-learned model; and training, by the one or more computing devices based on the first machine- learned model and the second subset, a second machine-learned model.

2. The computer-implemented method of claim 1, wherein training the second model comprises: initializing a first plurality7of parameters of the second machine-learned model based on one or more parameters of the first machine-learned model; and training a second plurality of parameters of the second machine-learned model using the second subset of the training dataset; wherein the second plurality of parameters is different from the first plurality7of parameters; and the first plurality of parameters is not updated using any data of the secondsubset of the training dataset.

3. The computer-implemented method of claim 1, wherein: the first machine-learned model was trained based at least in part on a third machine-learned model; the third machine-learned model was trained on a third plurality of data items; and the first entity is authorized to access each data item of the third plurality of data items.

4. The computer-implemented method of claim 3, wherein the first machine-learned model was trained by: initializing a first plurality of parameters of the first machine-learned model based on one or more parameters of the third machine-learned model; and training a second plurality of parameters of the first machine-learned model using the first subset of the training dataset; wherein the second plurality of parameters is different from the first plurality of parameters; and the first plurality of parameters is not updated using any data item of the third plurality of data items.

5. The computer-implemented method of claim 1, further comprising: receiving, by the one or more computing devices, an inference request associated with the first entity7; selecting, by the one or more computing devices based on the access authorization data, the second machine-learned model; generating, by the one or more computing devices using the second machine- learned model based on the inference request, an output; and providing, by the one or more computing devices to the first entity, the output.

6. The computer-implemented method of claim 1, further comprising: receiving, by the one or more computing devices, an inference request associated with the second entity; selecting, by the one or more computing devices based on the access authorization data, the first machine-learned model;generating, by the one or more computing devices using the first machine- learned model based on the inference request, an output; and providing, by the one or more computing devices to the second entity, the output.

7. A computer-implemented method for authorization-aware inference using a plurality of machine-learned models, comprising: receiving, by one or more computing devices, an inference request from a requester; obtaining, by the one or more computing devices, access authorization data that indicates that the requester is authorized to access one or more first data items and does not indicate that the requester is authorized to access one or more second data items; selecting, by the one or more computing devices based on the access authorization data, a machine-learned model from a plurality of respective machine- learned models that have been trained using a plurality of respective datasets, wherein the plurality of respective machine-learned models contains at least: a first machine-learned model that was trained using training data comprising the one or more second data items; and a second machine-learned model that was not trained using training data comprising the one or more second data items; generating, by the one or more computing devices based on the inference request using the selected machine-learned model, an output; and providing, by the one or more computing devices, the output to the requester; wherein the selected model is the second machine-learned model.

8. The computer-implemented method of claim 7, further comprising: selecting, by the one or more computing devices based on the access authorization data, an additional machine-learned model of the plurality of machine- learned models; wherein: the additional model is different from the second machine-learned model; the additional model was not trained using training data comprising the one or more second data items; andthe output is generated using the second machine-learned model and the additional machine-learned model.

9. The computer-implemented method of claim 8, wherein generating an output comprises: generating, by the one or more computing devices using the second machine- learned model based on the inference request, a first inference; generating, by the one or more computing devices using the additional machine-learned model based on the inference request, a second inference; and generating, by the one or more computing devices based on the first inference and second inference, the output.

10. The computer-implemented method of claim 9, wherein generating the output based on the first inference and second inference comprises machine-learned reconciliation of the first inference and second inference.1 1. The computer-implemented method of claim 10, wherein machine-learned reconciliation of the first inference and second inference comprises prompting a machine-learned sequence processing model with the first inference and second inference.

12. The computer-implemented method of claim 7, further comprising: retrieving, based at least in part on the access authorization data, at least one of the one or more first data items; wherein the output is generated based at least in part on the at least one retrieved data item.

13. The computer-implemented method of claim 7, wherein the requester is a first requester, and further comprising: obtaining, by the one or more computing devices, a second inference request from a second requester; obtaining, by the one or more computing devices, access authorization data indicating that the second requester is authorized to access the one or more second data items;selecting, by the one or more computing devices based on the access authorization data, the first machine-learned model; generating, by the one or more computing devices using the first machine- learned model, a second output; and providing, by the one or more computing devices, the second output to the second requester.

14. The computer-implemented method of claim 7, wherein the first machine-learned model was trained by: obtaining, by one or more computing devices, a training dataset comprising a plurality of data items; obtaining, by the one or more computing devices, access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item; determining, by the one or more computing devices based on the access authorization data, a first subset of the training dataset, wherein the access authorization data indicates that an entity is authorized to access each data item of the first subset; determining, by the one or more computing devices based on the access authorization data, a second subset of the training dataset, wherein the access authorization data does not indicate that the entity is authorized to access at least one data item of the second subset; training, by the one or more computing devices based on the first subset, the second machine-learned model; and training, by the one or more computing devices based on the second machine- learned model and the second subset, the first machine-learned model.

15. The computer-implemented method of claim 14, wherein training the first machine- learned model comprises: initializing a first plurality of parameters of the first machine-learned model based on one or more parameters of the second machine-learned model; and training a second plurality of parameters of the first machine-learned model using one or more of the second data items; wherein the second plurality of parameters is different from the first pluralityof parameters; and the first plurality of parameters is not updated using any data of the second data items.

16. The computer-implemented method of claim 7, wherein the requester comprises a user.

17. The computer-implemented method of claim 7, wherein the requester comprises a computing device associated with an access authorization account.

18. A computing system comprising one or more processors and one or more non- transitory computer-readable media storing instructions that are executable by the one or more processors to cause the computing system to perform operations, the operations comprising: obtaining a training dataset comprising a plurality of data items; obtaining access authorization data indicating, for each respective data item of the plurality of data items, that one or more respective authorized entities are authorized to access the respective data item; determining, based on the access authorization data, a first subset of the training dataset, wherein the access authorization data indicates that a first entity is authorized to access each data item of the first subset, and wherein the access authorization data indicates that a second entity is authorized to access each data item of the first subset; determining, based on the access authorization data, a second subset of the training dataset, wherein the access authorization data indicates that the first entity is authorized to access each data item of the second subset, and wherein the access authorization data does not indicate that the second entity is authorized to access each data item of the second subset; training, based on the first subset, a first machine-learned model; and training, based on the first machine-learned model and the second subset, a second machine-learned model.

19. The computing system of claim 18, wherein training the second model comprises: initializing a first plurality of parameters of the second machine-learned modelbased on one or more parameters of the first machine-learned model; and training a second plurality of parameters of the second machine-learned model using the second subset of the training dataset; wherein the second plurality of parameters is different from the first plurality of parameters; and the first plurality of parameters is not updated using any data of the second subset of the training dataset.

20. The computing system of claim 18, wherein: the first machine-learned model is trained based at least in part on a third machine-learned model; the third machine-learned model was trained on a third plurality of data items; and wherein the first entity is authorized to access each data item of the third plurality of data items.

Citation Information

Patent Citations

  • Enabling user-centered and contextually relevant interaction

    US20230245651A1